{"matches":[{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1701bd9ae2c8c60","name":"fonts-opensymbol","version":"4:102.12+LibO25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/fonts-opensymbol.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/fonts-opensymbol.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/fonts-opensymbol.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/fonts-opensymbol.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:fonts-opensymbol:fonts-opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:fonts-opensymbol:fonts_opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:fonts_opensymbol:fonts-opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:fonts_opensymbol:fonts_opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:fonts:fonts-opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:fonts:fonts_opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/fonts-opensymbol@4%3A102.12%2BLibO25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice%404%3A25.2.3-2%2Bdeb13u5","upstreams":[{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c4b5825229172d2b","name":"liblibreoffice-java","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblibreoffice-java.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblibreoffice-java.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblibreoffice-java.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblibreoffice-java.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblibreoffice-java:liblibreoffice-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:liblibreoffice-java:liblibreoffice_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:liblibreoffice_java:liblibreoffice-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:liblibreoffice_java:liblibreoffice_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:liblibreoffice:liblibreoffice-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:liblibreoffice:liblibreoffice_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblibreoffice-java@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"991ee90b430771d0","name":"libreoffice-base-core","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-base-core.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-core.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-base-core.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-core.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-base-core:libreoffice-base-core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base-core:libreoffice_base_core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_core:libreoffice-base-core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_core:libreoffice_base_core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice-base-core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice_base_core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice-base-core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice_base_core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-base-core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_base_core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-base-core@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"18881d9d9f463e8b","name":"libreoffice-base-drivers","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-base-drivers.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-drivers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-base-drivers.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-drivers.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-base-drivers:libreoffice-base-drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base-drivers:libreoffice_base_drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_drivers:libreoffice-base-drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_drivers:libreoffice_base_drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice-base-drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice_base_drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice-base-drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice_base_drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-base-drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_base_drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-base-drivers@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"501111a6ef4dc0d8","name":"libreoffice-base-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-base-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-base-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-base-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-base-nogui:libreoffice-base-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base-nogui:libreoffice_base_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_nogui:libreoffice-base-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_nogui:libreoffice_base_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice-base-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice_base_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice-base-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice_base_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-base-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_base_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-base-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7c2f514218b3576e","name":"libreoffice-calc-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-calc-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-calc-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-calc-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-calc-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-calc-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-calc-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-calc-nogui:libreoffice-calc-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-calc-nogui:libreoffice_calc_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_calc_nogui:libreoffice-calc-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_calc_nogui:libreoffice_calc_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-calc:libreoffice-calc-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-calc:libreoffice_calc_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_calc:libreoffice-calc-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_calc:libreoffice_calc_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-calc-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_calc_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-calc-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bbefb6e067e89429","name":"libreoffice-common","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-common.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-common.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-common.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.list"},{"path":"/var/lib/dpkg/info/libreoffice-common.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.postinst"},{"path":"/var/lib/dpkg/info/libreoffice-common.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.postrm"},{"path":"/var/lib/dpkg/info/libreoffice-common.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.preinst"},{"path":"/var/lib/dpkg/info/libreoffice-common.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.prerm"},{"path":"/var/lib/dpkg/info/libreoffice-common.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-common:libreoffice-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-common:libreoffice_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_common:libreoffice-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_common:libreoffice_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-common@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d6e993d5bbfad993","name":"libreoffice-core-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-core-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-core-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-core-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-core-nogui.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-core-nogui:libreoffice-core-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-core-nogui:libreoffice_core_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_core_nogui:libreoffice-core-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_core_nogui:libreoffice_core_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-core:libreoffice-core-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-core:libreoffice_core_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_core:libreoffice-core-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_core:libreoffice_core_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-core-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_core_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-core-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"890ac2cbd45481b2","name":"libreoffice-draw-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-draw-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-draw-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-draw-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-draw-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-draw-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-draw-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-draw-nogui:libreoffice-draw-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-draw-nogui:libreoffice_draw_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_draw_nogui:libreoffice-draw-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_draw_nogui:libreoffice_draw_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-draw:libreoffice-draw-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-draw:libreoffice_draw_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_draw:libreoffice-draw-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_draw:libreoffice_draw_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-draw-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_draw_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-draw-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ee5e48d57677fd7d","name":"libreoffice-impress-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-impress-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-impress-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-impress-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-impress-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-impress-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-impress-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-impress-nogui:libreoffice-impress-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-impress-nogui:libreoffice_impress_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_impress_nogui:libreoffice-impress-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_impress_nogui:libreoffice_impress_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-impress:libreoffice-impress-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-impress:libreoffice_impress_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_impress:libreoffice-impress-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_impress:libreoffice_impress_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-impress-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_impress_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-impress-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0015e661a6b657e4","name":"libreoffice-java-common","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-java-common.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-java-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-java-common.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-java-common.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-java-common:libreoffice-java-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-java-common:libreoffice_java_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_java_common:libreoffice-java-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_java_common:libreoffice_java_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-java:libreoffice-java-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-java:libreoffice_java_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_java:libreoffice-java-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_java:libreoffice_java_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-java-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_java_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-java-common@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0b7808965ccf0eb9","name":"libreoffice-math-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-math-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-math-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-math-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-math-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-math-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-math-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-math-nogui:libreoffice-math-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-math-nogui:libreoffice_math_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_math_nogui:libreoffice-math-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_math_nogui:libreoffice_math_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-math:libreoffice-math-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-math:libreoffice_math_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_math:libreoffice-math-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_math:libreoffice_math_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-math-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_math_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-math-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c23ab5f2aa9bbf8","name":"libreoffice-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-nogui.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-nogui:libreoffice-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-nogui:libreoffice_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_nogui:libreoffice-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_nogui:libreoffice_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"065aa061da4a2271","name":"libreoffice-report-builder-bin-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-report-builder-bin-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-report-builder-bin-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-report-builder-bin-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-report-builder-bin-nogui.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-report-builder-bin-nogui:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report-builder-bin-nogui:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder_bin_nogui:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder_bin_nogui:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report-builder-bin:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report-builder-bin:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder_bin:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder_bin:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report-builder:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report-builder:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-report-builder-bin-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c42d0c7d012589a","name":"libreoffice-style-colibre","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-style-colibre.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-style-colibre.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-style-colibre.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-style-colibre.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-style-colibre:libreoffice-style-colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-style-colibre:libreoffice_style_colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_style_colibre:libreoffice-style-colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_style_colibre:libreoffice_style_colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-style:libreoffice-style-colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-style:libreoffice_style_colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_style:libreoffice-style-colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_style:libreoffice_style_colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-style-colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_style_colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-style-colibre@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"507f67a1aba84c6f","name":"libreoffice-uiconfig-calc","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-calc.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-calc.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-calc.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-calc.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-uiconfig-calc:libreoffice-uiconfig-calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig-calc:libreoffice_uiconfig_calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_calc:libreoffice-uiconfig-calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_calc:libreoffice_uiconfig_calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice-uiconfig-calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice_uiconfig_calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice-uiconfig-calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice_uiconfig_calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-uiconfig-calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_uiconfig_calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-uiconfig-calc@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"86acdf8e5a25399b","name":"libreoffice-uiconfig-common","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-common.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-common.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-common.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-uiconfig-common:libreoffice-uiconfig-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig-common:libreoffice_uiconfig_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_common:libreoffice-uiconfig-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_common:libreoffice_uiconfig_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice-uiconfig-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice_uiconfig_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice-uiconfig-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice_uiconfig_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-uiconfig-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_uiconfig_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-uiconfig-common@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b2d3cc35f7715bb8","name":"libreoffice-uiconfig-draw","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-draw.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-draw.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-draw.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-draw.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-uiconfig-draw:libreoffice-uiconfig-draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig-draw:libreoffice_uiconfig_draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_draw:libreoffice-uiconfig-draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_draw:libreoffice_uiconfig_draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice-uiconfig-draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice_uiconfig_draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice-uiconfig-draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice_uiconfig_draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-uiconfig-draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_uiconfig_draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-uiconfig-draw@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"838ef30045666ce0","name":"libreoffice-uiconfig-impress","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-impress.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-impress.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-impress.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-impress.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-uiconfig-impress:libreoffice-uiconfig-impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig-impress:libreoffice_uiconfig_impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_impress:libreoffice-uiconfig-impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_impress:libreoffice_uiconfig_impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice-uiconfig-impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice_uiconfig_impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice-uiconfig-impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice_uiconfig_impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-uiconfig-impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_uiconfig_impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-uiconfig-impress@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b2a463656e4e981d","name":"libreoffice-uiconfig-math","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-math.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-math.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-math.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-math.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-uiconfig-math:libreoffice-uiconfig-math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig-math:libreoffice_uiconfig_math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_math:libreoffice-uiconfig-math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_math:libreoffice_uiconfig_math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice-uiconfig-math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice_uiconfig_math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice-uiconfig-math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice_uiconfig_math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-uiconfig-math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_uiconfig_math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-uiconfig-math@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f4bdece6399f1d44","name":"libreoffice-writer-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-writer-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-writer-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-writer-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-writer-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-writer-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-writer-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-writer-nogui:libreoffice-writer-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-writer-nogui:libreoffice_writer_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_writer_nogui:libreoffice-writer-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_writer_nogui:libreoffice_writer_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-writer:libreoffice-writer-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-writer:libreoffice_writer_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_writer:libreoffice-writer-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_writer:libreoffice_writer_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-writer-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_writer_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-writer-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f82f66b1d93b6e99","name":"libuno-cppu3t64","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuno-cppu3t64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppu3t64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuno-cppu3t64.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppu3t64.list"},{"path":"/var/lib/dpkg/info/libuno-cppu3t64.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppu3t64.shlibs"},{"path":"/var/lib/dpkg/info/libuno-cppu3t64.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppu3t64.symbols"},{"path":"/var/lib/dpkg/info/libuno-cppu3t64.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppu3t64.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuno-cppu3t64:libuno-cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-cppu3t64:libuno_cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppu3t64:libuno-cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppu3t64:libuno_cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno-cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno_cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuno-cppu3t64@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"277cf190101b1d44","name":"libuno-cppuhelpergcc3-3t64","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.list"},{"path":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.shlibs"},{"path":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.symbols"},{"path":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuno-cppuhelpergcc3-3t64:libuno-cppuhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-cppuhelpergcc3-3t64:libuno_cppuhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppuhelpergcc3_3t64:libuno-cppuhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppuhelpergcc3_3t64:libuno_cppuhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-cppuhelpergcc3:libuno-cppuhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-cppuhelpergcc3:libuno_cppuhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppuhelpergcc3:libuno-cppuhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppuhelpergcc3:libuno_cppuhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno-cppuhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno_cppuhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuno-cppuhelpergcc3-3t64@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bbf262193bc0b0f7","name":"libuno-purpenvhelpergcc3-3t64","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.list"},{"path":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.shlibs"},{"path":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.symbols"},{"path":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuno-purpenvhelpergcc3-3t64:libuno-purpenvhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-purpenvhelpergcc3-3t64:libuno_purpenvhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_purpenvhelpergcc3_3t64:libuno-purpenvhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_purpenvhelpergcc3_3t64:libuno_purpenvhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-purpenvhelpergcc3:libuno-purpenvhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-purpenvhelpergcc3:libuno_purpenvhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_purpenvhelpergcc3:libuno-purpenvhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_purpenvhelpergcc3:libuno_purpenvhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno-purpenvhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno_purpenvhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuno-purpenvhelpergcc3-3t64@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"245196f89099084f","name":"libuno-sal3t64","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuno-sal3t64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-sal3t64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuno-sal3t64.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-sal3t64.list"},{"path":"/var/lib/dpkg/info/libuno-sal3t64.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-sal3t64.shlibs"},{"path":"/var/lib/dpkg/info/libuno-sal3t64.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-sal3t64.symbols"},{"path":"/var/lib/dpkg/info/libuno-sal3t64.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-sal3t64.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuno-sal3t64:libuno-sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-sal3t64:libuno_sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_sal3t64:libuno-sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_sal3t64:libuno_sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno-sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno_sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuno-sal3t64@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e45d7926780dd68","name":"libuno-salhelpergcc3-3t64","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.list"},{"path":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.shlibs"},{"path":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.symbols"},{"path":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuno-salhelpergcc3-3t64:libuno-salhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-salhelpergcc3-3t64:libuno_salhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_salhelpergcc3_3t64:libuno-salhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_salhelpergcc3_3t64:libuno_salhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-salhelpergcc3:libuno-salhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-salhelpergcc3:libuno_salhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_salhelpergcc3:libuno-salhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_salhelpergcc3:libuno_salhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno-salhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno_salhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuno-salhelpergcc3-3t64@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e8e43bcf110867ce","name":"libunoloader-java","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libunoloader-java.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libunoloader-java.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libunoloader-java.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libunoloader-java.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libunoloader-java:libunoloader-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libunoloader-java:libunoloader_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libunoloader_java:libunoloader-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libunoloader_java:libunoloader_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libunoloader:libunoloader-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libunoloader:libunoloader_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libunoloader-java@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b542f276d600fe07","name":"python3-uno","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-uno.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-uno.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-uno.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-uno.list"},{"path":"/var/lib/dpkg/info/python3-uno.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-uno.postinst"},{"path":"/var/lib/dpkg/info/python3-uno.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-uno.preinst"},{"path":"/var/lib/dpkg/info/python3-uno.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-uno.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-uno:python3-uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3-uno:python3_uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3_uno:python3-uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3_uno:python3_uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-uno@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5007583eff4cae19","name":"uno-libs-private","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/uno-libs-private.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/uno-libs-private.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/uno-libs-private.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/uno-libs-private.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:uno-libs-private:uno-libs-private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno-libs-private:uno_libs_private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno_libs_private:uno-libs-private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno_libs_private:uno_libs_private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno-libs:uno-libs-private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno-libs:uno_libs_private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno_libs:uno-libs-private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno_libs:uno_libs_private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno:uno-libs-private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno:uno_libs_private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/uno-libs-private@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0193eceff7def065","name":"ure","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/ure.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ure.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ure.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ure.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:ure:ure:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ure@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-10583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10583","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.9341500000000003},"relatedVulnerabilities":[{"id":"CVE-2018-10583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10583","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2020/Oct/26","http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/","https://access.redhat.com/errata/RHSA-2018:3054","https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3E","https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2018-10583","https://usn.ubuntu.com/3883-1/","https://www.exploit-db.com/exploits/44564/"],"description":"An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10583","epss":0.78683,"percentile":0.99543,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10583","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9a05e0f5aa69cb96","name":"ure-java","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/ure-java.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ure-java.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ure-java.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ure-java.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:ure-java:ure-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:ure-java:ure_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:ure_java:ure-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:ure_java:ure_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:ure:ure-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:ure:ure_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ure-java@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2026-11856","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the  `Authorization:` header field meant for `hostA`, to `hostB`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11856","epss":0.01064,"percentile":0.609,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":1.0001600000000002},"relatedVulnerabilities":[{"id":"CVE-2026-11856","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11856","epss":0.01064,"percentile":0.609,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-9079","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9079","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9079","epss":0.01064,"percentile":0.609,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":1.0001600000000002},"relatedVulnerabilities":[{"id":"CVE-2026-9079","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9079","epss":0.01064,"percentile":0.609,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9079","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-11856","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the  `Authorization:` header field meant for `hostA`, to `hostB`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11856","epss":0.01064,"percentile":0.609,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":1.0001600000000002},"relatedVulnerabilities":[{"id":"CVE-2026-11856","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11856","epss":0.01064,"percentile":0.609,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-9079","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9079","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9079","epss":0.01064,"percentile":0.609,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":1.0001600000000002},"relatedVulnerabilities":[{"id":"CVE-2026-9079","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9079","epss":0.01064,"percentile":0.609,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9079","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2019-9543","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9543","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JArithmeticDecoder::decodeBit.","cvss":[],"epss":[{"cve":"CVE-2019-9543","epss":0.03312,"percentile":0.87188,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-9543","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.9935999999999998},"relatedVulnerabilities":[{"id":"CVE-2019-9543","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9543","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/107238","https://gitlab.freedesktop.org/poppler/poppler/issues/730","https://research.loginsoft.com/bugs/recursive-function-call-in-function-jbig2streamreadgenericbitmap-poppler-0-74-0/"],"description":"An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JArithmeticDecoder::decodeBit.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-9543","epss":0.03312,"percentile":0.87188,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-9543","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"poppler","version":"25.03.0-5+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-9543","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f9378ee2c5fb55fb","name":"libpoppler147","version":"25.03.0-5+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpoppler147:libpoppler147:25.03.0-5\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpoppler147@25.03.0-5%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=poppler","upstreams":[{"name":"poppler"}]}},{"vulnerability":{"id":"CVE-2025-59375","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59375","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59375","epss":0.01279,"percentile":0.66764,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-59375","cwe":"CWE-770","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.95925},"relatedVulnerabilities":[{"id":"CVE-2025-59375","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59375","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/blob/676a4c531ec768732fac215da9730b5f50fbd2bf/expat/Changes#L45-L74","https://github.com/libexpat/libexpat/blob/R_2_7_2/expat/Changes","https://github.com/libexpat/libexpat/issues/1018","https://github.com/libexpat/libexpat/pull/1034","https://issues.oss-fuzz.com/issues/439133977","http://www.openwall.com/lists/oss-security/2025/09/16/2","http://www.openwall.com/lists/oss-security/2026/05/01/5","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html"],"description":"libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59375","epss":0.01279,"percentile":0.66764,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-59375","cwe":"CWE-770","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-59375","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-10536","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10536","epss":0.00891,"percentile":0.55381,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.83754},"relatedVulnerabilities":[{"id":"CVE-2026-10536","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10536","epss":0.00891,"percentile":0.55381,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-10536","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10536","epss":0.00891,"percentile":0.55381,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.83754},"relatedVulnerabilities":[{"id":"CVE-2026-10536","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10536","epss":0.00891,"percentile":0.55381,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-13151","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-13151","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-13151","epss":0.01109,"percentile":0.62211,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["4.20.0-2+deb13u1"],"state":"fixed","available":[{"version":"4.20.0-2+deb13u1","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.8317499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-13151","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13151","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.com/gnutls/libtasn1","https://gitlab.com/gnutls/libtasn1/-/merge_requests/121","http://www.openwall.com/lists/oss-security/2026/01/08/5","https://www.kb.cert.org/vuls/id/271649"],"description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-13151","epss":0.01109,"percentile":0.62211,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libtasn1-6","version":"4.20.0-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-13151","versionConstraint":"< 4.20.0-2+deb13u1 (deb)"},"fix":{"suggestedVersion":"4.20.0-2+deb13u1"}}],"artifact":{"id":"9e90f6ec0fa8d891","name":"libtasn1-6","version":"4.20.0-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtasn1-6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtasn1-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtasn1-6:libtasn1-6:4.20.0-2:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1-6:libtasn1_6:4.20.0-2:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1-6:4.20.0-2:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1_6:4.20.0-2:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1-6:4.20.0-2:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1_6:4.20.0-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtasn1-6@4.20.0-2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8927","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8927","epss":0.00752,"percentile":0.50877,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.68056},"relatedVulnerabilities":[{"id":"CVE-2026-8927","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8927","epss":0.00752,"percentile":0.50877,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8927","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8927","epss":0.00752,"percentile":0.50877,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.68056},"relatedVulnerabilities":[{"id":"CVE-2026-8927","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8927","epss":0.00752,"percentile":0.50877,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8924","epss":0.00649,"percentile":0.47031,"date":"2026-07-18"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.587345},"relatedVulnerabilities":[{"id":"CVE-2026-8924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8924","epss":0.00649,"percentile":0.47031,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8924","epss":0.00649,"percentile":0.47031,"date":"2026-07-18"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.587345},"relatedVulnerabilities":[{"id":"CVE-2026-8924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8924","epss":0.00649,"percentile":0.47031,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8926","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8926","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8926","epss":0.0061,"percentile":0.45234,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.55205},"relatedVulnerabilities":[{"id":"CVE-2026-8926","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username(without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8926","epss":0.0061,"percentile":0.45234,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8926","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8926","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8926","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8926","epss":0.0061,"percentile":0.45234,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.55205},"relatedVulnerabilities":[{"id":"CVE-2026-8926","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username(without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8926","epss":0.0061,"percentile":0.45234,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8926","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2017-7475","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-7475","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.","cvss":[],"epss":[{"cve":"CVE-2017-7475","epss":0.01824,"percentile":0.7639,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5471999999999999},"relatedVulnerabilities":[{"id":"CVE-2017-7475","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7475","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/oss-sec/2017/q2/151","https://bugs.freedesktop.org/show_bug.cgi?id=100763","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-7475","epss":0.01824,"percentile":0.7639,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"cairo","version":"1.18.4-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-7475","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2efbf400f5d2550c","name":"libcairo2","version":"1.18.4-1+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcairo2:libcairo2:1.18.4-1\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo2@1.18.4-1%2Bb1?arch=amd64&distro=debian-13.5&upstream=cairo%401.18.4-1","upstreams":[{"name":"cairo","version":"1.18.4-1"}]}},{"vulnerability":{"id":"CVE-2019-9545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9545","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.","cvss":[],"epss":[{"cve":"CVE-2019-9545","epss":0.01824,"percentile":0.76388,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-9545","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5471999999999999},"relatedVulnerabilities":[{"id":"CVE-2019-9545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9545","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.freedesktop.org/poppler/poppler/issues/731","https://research.loginsoft.com/bugs/recursive-function-call-in-function-jbig2streamreadtextregion-poppler-0-74-0/"],"description":"An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-9545","epss":0.01824,"percentile":0.76388,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-9545","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"poppler","version":"25.03.0-5+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-9545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f9378ee2c5fb55fb","name":"libpoppler147","version":"25.03.0-5+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpoppler147:libpoppler147:25.03.0-5\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpoppler147@25.03.0-5%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=poppler","upstreams":[{"name":"poppler"}]}},{"vulnerability":{"id":"CVE-2026-3805","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3805","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3805","epss":0.00715,"percentile":0.49603,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3805","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.53625},"relatedVulnerabilities":[{"id":"CVE-2026-3805","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3805","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-3805.html","https://curl.se/docs/CVE-2026-3805.json","https://hackerone.com/reports/3591944","http://www.openwall.com/lists/oss-security/2026/03/11/4"],"description":"When doing a second SMB request to the same host again, curl would wrongly use\na data pointer pointing into already freed memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3805","epss":0.00715,"percentile":0.49603,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3805","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3805","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-3805","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3805","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3805","epss":0.00715,"percentile":0.49603,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3805","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.53625},"relatedVulnerabilities":[{"id":"CVE-2026-3805","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3805","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-3805.html","https://curl.se/docs/CVE-2026-3805.json","https://hackerone.com/reports/3591944","http://www.openwall.com/lists/oss-security/2026/03/11/4"],"description":"When doing a second SMB request to the same host again, curl would wrongly use\na data pointer pointing into already freed memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3805","epss":0.00715,"percentile":0.49603,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3805","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3805","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2019-6988","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6988","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.","cvss":[],"epss":[{"cve":"CVE-2019-6988","epss":0.01724,"percentile":0.74981,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5172},"relatedVulnerabilities":[{"id":"CVE-2019-6988","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6988","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106785","https://github.com/uclouvain/openjpeg/issues/1178"],"description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-6988","epss":0.01724,"percentile":0.74981,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-6988","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.00613,"percentile":0.4535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.46894500000000006},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.00613,"percentile":0.4535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.00613,"percentile":0.4535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.46894500000000006},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.00613,"percentile":0.4535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.00613,"percentile":0.4535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.46894500000000006},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.00613,"percentile":0.4535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.00613,"percentile":0.4535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.46894500000000006},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.00613,"percentile":0.4535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.00613,"percentile":0.4535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.46894500000000006},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.00613,"percentile":0.4535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-12064","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12064","epss":0.00574,"percentile":0.43557,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.4305},"relatedVulnerabilities":[{"id":"CVE-2026-12064","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12064","epss":0.00574,"percentile":0.43557,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-12064","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12064","epss":0.00574,"percentile":0.43557,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.4305},"relatedVulnerabilities":[{"id":"CVE-2026-12064","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12064","epss":0.00574,"percentile":0.43557,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-5773","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5773","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different 'share' than the new subsequent transfer should.  This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5773","epss":0.00549,"percentile":0.42266,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-918","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.41174999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-5773","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5773","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-5773.html","https://curl.se/docs/CVE-2026-5773.json","https://hackerone.com/reports/3650689","http://www.openwall.com/lists/oss-security/2026/04/29/9"],"description":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5773","epss":0.00549,"percentile":0.42266,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-918","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-5773","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-5773","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5773","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different 'share' than the new subsequent transfer should.  This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5773","epss":0.00549,"percentile":0.42266,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-918","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.41174999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-5773","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5773","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-5773.html","https://curl.se/docs/CVE-2026-5773.json","https://hackerone.com/reports/3650689","http://www.openwall.com/lists/oss-security/2026/04/29/9"],"description":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5773","epss":0.00549,"percentile":0.42266,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-918","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-5773","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-0990","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0990","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0990","epss":0.00755,"percentile":0.50999,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0990","cwe":"CWE-674","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":["2.12.7+dfsg+really2.9.14-2.1+deb13u3"],"state":"fixed","available":[{"version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.41147500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-0990","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0990","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-0990","https://bugzilla.redhat.com/show_bug.cgi?id=2429959","https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"],"description":"A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0990","epss":0.00755,"percentile":0.50999,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0990","cwe":"CWE-674","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-0990","versionConstraint":"< 2.12.7+dfsg+really2.9.14-2.1+deb13u3 (deb)"},"fix":{"suggestedVersion":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"}}],"artifact":{"id":"07fee9125970d2ca","name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8286","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8286","epss":0.0052,"percentile":0.40718,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.40559999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-8286","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8286","epss":0.0052,"percentile":0.40718,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8286","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8286","epss":0.0052,"percentile":0.40718,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.40559999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-8286","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8286","epss":0.0052,"percentile":0.40718,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-7774","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7774","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7774","epss":0.00622,"percentile":0.45825,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.37009},"relatedVulnerabilities":[{"id":"CVE-2026-7774","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7774","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2","https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d","https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc","https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da","https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558","https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf","https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609","https://github.com/python/cpython/issues/149486","https://github.com/python/cpython/pull/149487","https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/","http://www.openwall.com/lists/oss-security/2026/06/04/9"],"description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7774","epss":0.00622,"percentile":0.45825,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7774","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-7774","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7774","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7774","epss":0.00622,"percentile":0.45825,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.37009},"relatedVulnerabilities":[{"id":"CVE-2026-7774","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7774","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2","https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d","https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc","https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da","https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558","https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf","https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609","https://github.com/python/cpython/issues/149486","https://github.com/python/cpython/pull/149487","https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/","http://www.openwall.com/lists/oss-security/2026/06/04/9"],"description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7774","epss":0.00622,"percentile":0.45825,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7774","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-7774","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7774","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7774","epss":0.00622,"percentile":0.45825,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.37009},"relatedVulnerabilities":[{"id":"CVE-2026-7774","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7774","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2","https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d","https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc","https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da","https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558","https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf","https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609","https://github.com/python/cpython/issues/149486","https://github.com/python/cpython/pull/149487","https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/","http://www.openwall.com/lists/oss-security/2026/06/04/9"],"description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7774","epss":0.00622,"percentile":0.45825,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7774","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-7774","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7774","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7774","epss":0.00622,"percentile":0.45825,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.37009},"relatedVulnerabilities":[{"id":"CVE-2026-7774","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7774","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2","https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d","https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc","https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da","https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558","https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf","https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609","https://github.com/python/cpython/issues/149486","https://github.com/python/cpython/pull/149487","https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/","http://www.openwall.com/lists/oss-security/2026/06/04/9"],"description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7774","epss":0.00622,"percentile":0.45825,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7774","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-7774","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7774","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7774","epss":0.00622,"percentile":0.45825,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.37009},"relatedVulnerabilities":[{"id":"CVE-2026-7774","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7774","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2","https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d","https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc","https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da","https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558","https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf","https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609","https://github.com/python/cpython/issues/149486","https://github.com/python/cpython/pull/149487","https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/","http://www.openwall.com/lists/oss-security/2026/06/04/9"],"description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7774","epss":0.00622,"percentile":0.45825,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7774","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-9080","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9080","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9080","epss":0.00494,"percentile":0.39149,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.36556},"relatedVulnerabilities":[{"id":"CVE-2026-9080","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9080","epss":0.00494,"percentile":0.39149,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9080","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-9080","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9080","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9080","epss":0.00494,"percentile":0.39149,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.36556},"relatedVulnerabilities":[{"id":"CVE-2026-9080","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9080","epss":0.00494,"percentile":0.39149,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9080","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-25556","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-25556","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception. Callers (including the barcode decoding path in fz_decode_barcode_from_display_list) also drop the same pixmap in cleanup, resulting in a double-free that can corrupt the heap and crash the process. This issue affects applications that enable and use MuPDF barcode decoding and can be triggered by processing crafted input that causes a rendering-time error while decoding barcodes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25556","epss":0.00477,"percentile":0.38139,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-25556","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.35775},"relatedVulnerabilities":[{"id":"CVE-2026-25556","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25556","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=709029","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=d4743b6092d513321c23c6f7fe5cff87cde043c1","https://mupdf.com/","https://www.vulncheck.com/advisories/mupdf-barcode-decoding-double-free"],"description":"MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception. Callers (including the barcode decoding path in fz_decode_barcode_from_display_list) also drop the same pixmap in cleanup, resulting in a double-free that can corrupt the heap and crash the process. This issue affects applications that enable and use MuPDF barcode decoding and can be triggered by processing crafted input that causes a rendering-time error while decoding barcodes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25556","epss":0.00477,"percentile":0.38139,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-25556","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-25556","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6de3a4b2ce25dd7","name":"libmupdf25.1","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.list"},{"path":"/var/lib/dpkg/info/libmupdf25.1.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.shlibs"},{"path":"/var/lib/dpkg/info/libmupdf25.1.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.symbols"},{"path":"/var/lib/dpkg/info/libmupdf25.1.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmupdf25.1:libmupdf25.1:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmupdf25.1@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2026-25556","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-25556","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception. Callers (including the barcode decoding path in fz_decode_barcode_from_display_list) also drop the same pixmap in cleanup, resulting in a double-free that can corrupt the heap and crash the process. This issue affects applications that enable and use MuPDF barcode decoding and can be triggered by processing crafted input that causes a rendering-time error while decoding barcodes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25556","epss":0.00477,"percentile":0.38139,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-25556","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.35775},"relatedVulnerabilities":[{"id":"CVE-2026-25556","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25556","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=709029","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=d4743b6092d513321c23c6f7fe5cff87cde043c1","https://mupdf.com/","https://www.vulncheck.com/advisories/mupdf-barcode-decoding-double-free"],"description":"MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception. Callers (including the barcode decoding path in fz_decode_barcode_from_display_list) also drop the same pixmap in cleanup, resulting in a double-free that can corrupt the heap and crash the process. This issue affects applications that enable and use MuPDF barcode decoding and can be triggered by processing crafted input that causes a rendering-time error while decoding barcodes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25556","epss":0.00477,"percentile":0.38139,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-25556","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-25556","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a8856e00526f091d","name":"python3-mupdf","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-mupdf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-mupdf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.list"},{"path":"/var/lib/dpkg/info/python3-mupdf.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.postinst"},{"path":"/var/lib/dpkg/info/python3-mupdf.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3-mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-mupdf@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2017-17740","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-17740","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.","cvss":[],"epss":[{"cve":"CVE-2017-17740","epss":0.07022,"percentile":0.93456,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3511},"relatedVulnerabilities":[{"id":"CVE-2017-17740","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-17740","namespace":"nvd:cpe","severity":"High","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://www.openldap.org/its/index.cgi/Incoming?id=8759","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-17740","epss":0.07022,"percentile":0.93456,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-17740","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34614e72922d8e4b","name":"libldap2","version":"2.6.10+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.5&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2024-52616","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00681,"percentile":0.48315,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.350715},"relatedVulnerabilities":[{"id":"CVE-2024-52616","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00681,"percentile":0.48315,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"}}],"artifact":{"id":"337bbef46c41fed2","name":"libavahi-client3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2024-52616","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00681,"percentile":0.48315,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.350715},"relatedVulnerabilities":[{"id":"CVE-2024-52616","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00681,"percentile":0.48315,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1eab38231de446ba","name":"libavahi-common-data","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2024-52616","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00681,"percentile":0.48315,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.350715},"relatedVulnerabilities":[{"id":"CVE-2024-52616","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00681,"percentile":0.48315,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eaca5e0133dcdd02","name":"libavahi-common3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-14819","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14819","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When doing TLS related transfers with reused easy or multi handles and altering the  `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14819","epss":0.00679,"percentile":0.48256,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14819","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.349685},"relatedVulnerabilities":[{"id":"CVE-2025-14819","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14819","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-14819.html","https://curl.se/docs/CVE-2025-14819.json","http://www.openwall.com/lists/oss-security/2026/01/07/5"],"description":"When doing TLS related transfers with reused easy or multi handles and\naltering the  `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally\nreuse a CA store cached in memory for which the partial chain option was\nreversed. Contrary to the user's wishes and expectations. This could make\nlibcurl find and accept a trust chain that it otherwise would not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14819","epss":0.00679,"percentile":0.48256,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14819","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14819","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-14819","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14819","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When doing TLS related transfers with reused easy or multi handles and altering the  `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14819","epss":0.00679,"percentile":0.48256,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14819","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.349685},"relatedVulnerabilities":[{"id":"CVE-2025-14819","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14819","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-14819.html","https://curl.se/docs/CVE-2025-14819.json","http://www.openwall.com/lists/oss-security/2026/01/07/5"],"description":"When doing TLS related transfers with reused easy or multi handles and\naltering the  `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally\nreuse a CA store cached in memory for which the partial chain option was\nreversed. Contrary to the user's wishes and expectations. This could make\nlibcurl find and accept a trust chain that it otherwise would not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14819","epss":0.00679,"percentile":0.48256,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14819","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14819","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-6253","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6253","epss":0.00639,"percentile":0.46542,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.348255},"relatedVulnerabilities":[{"id":"CVE-2026-6253","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6253","epss":0.00639,"percentile":0.46542,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-6253","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6253","epss":0.00639,"percentile":0.46542,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.348255},"relatedVulnerabilities":[{"id":"CVE-2026-6253","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6253","epss":0.00639,"percentile":0.46542,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.00433,"percentile":0.35124,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.33990499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.00433,"percentile":0.35124,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.00433,"percentile":0.35124,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.33990499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.00433,"percentile":0.35124,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.00433,"percentile":0.35124,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.33990499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.00433,"percentile":0.35124,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.00433,"percentile":0.35124,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.33990499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.00433,"percentile":0.35124,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.00433,"percentile":0.35124,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.33990499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.00433,"percentile":0.35124,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00433,"percentile":0.3506,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.33990499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00433,"percentile":0.3506,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00433,"percentile":0.3506,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.33990499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00433,"percentile":0.3506,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00433,"percentile":0.3506,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.33990499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00433,"percentile":0.3506,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00433,"percentile":0.3506,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.33990499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00433,"percentile":0.3506,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00433,"percentile":0.3506,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.33990499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00433,"percentile":0.3506,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-6653","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6653","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6653","epss":0.00348,"percentile":0.27093,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","source":"security@ubuntu.com","type":"Secondary"},{"cve":"CVE-2026-6653","cwe":"CWE-611","source":"security@ubuntu.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.32712},"relatedVulnerabilities":[{"id":"CVE-2026-6653","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6653","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"],"description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"security@ubuntu.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6653","epss":0.00348,"percentile":0.27093,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","source":"security@ubuntu.com","type":"Secondary"},{"cve":"CVE-2026-6653","cwe":"CWE-611","source":"security@ubuntu.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-6653","versionConstraint":"none (unknown)"}}],"artifact":{"id":"07fee9125970d2ca","name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-38076","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-38076","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38076","epss":0.00432,"percentile":0.34987,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-38076","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.32399999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-38076","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-38076","namespace":"nvd:cpe","severity":"High","urls":["http://artifex.com","https://gist.github.com/dkjsone/c237b83ffa9ebd7028b5db7f410fcf78","https://github.com/ArtifexSoftware/jbig2dec"],"description":"An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38076","epss":0.00432,"percentile":0.34987,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-38076","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"jbig2dec","version":"0.20-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-38076","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3aea2e5950cacb25","name":"libjbig2dec0","version":"0.20-1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libjbig2dec0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libjbig2dec0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libjbig2dec0:libjbig2dec0:0.20-1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjbig2dec0@0.20-1%2Bb3?arch=amd64&distro=debian-13.5&upstream=jbig2dec%400.20-1","upstreams":[{"name":"jbig2dec","version":"0.20-1"}]}},{"vulnerability":{"id":"CVE-2026-24882","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.32206500000000005},"relatedVulnerabilities":[{"id":"CVE-2026-24882","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","namespace":"nvd:cpe","severity":"High","urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d73c99dbc97f6ec0","name":"dirmngr","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/dirmngr@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2026-24882","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.32206500000000005},"relatedVulnerabilities":[{"id":"CVE-2026-24882","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","namespace":"nvd:cpe","severity":"High","urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ced4de0e43890bd3","name":"gnupg","version":"2.4.7-21+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gnupg:gnupg:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg@2.4.7-21%2Bdeb13u1?arch=all&distro=debian-13.5&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-24882","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.32206500000000005},"relatedVulnerabilities":[{"id":"CVE-2026-24882","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","namespace":"nvd:cpe","severity":"High","urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"}}],"artifact":{"id":"deb1d413d83f82b8","name":"gnupg-l10n","version":"2.4.7-21+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-l10n@2.4.7-21%2Bdeb13u1?arch=all&distro=debian-13.5&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-24882","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.32206500000000005},"relatedVulnerabilities":[{"id":"CVE-2026-24882","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","namespace":"nvd:cpe","severity":"High","urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cd76d9c17a1cf27f","name":"gpg","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.list"},{"path":"/var/lib/dpkg/info/gpg.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.postinst"},{"path":"/var/lib/dpkg/info/gpg.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.postrm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpg:gpg:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2026-24882","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.32206500000000005},"relatedVulnerabilities":[{"id":"CVE-2026-24882","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","namespace":"nvd:cpe","severity":"High","urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2660f16d4b2ce1d7","name":"gpg-agent","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-agent@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2026-24882","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.32206500000000005},"relatedVulnerabilities":[{"id":"CVE-2026-24882","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","namespace":"nvd:cpe","severity":"High","urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c44d319fa06436ce","name":"gpgconf","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgconf@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2026-24882","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.32206500000000005},"relatedVulnerabilities":[{"id":"CVE-2026-24882","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","namespace":"nvd:cpe","severity":"High","urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24882","epss":0.00421,"percentile":0.34216,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-24882","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"}}],"artifact":{"id":"321974a38b0687e6","name":"gpgsm","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgsm@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2023-39329","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39329","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39329","epss":0.00559,"percentile":0.42836,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.321425},"relatedVulnerabilities":[{"id":"CVE-2023-39329","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39329","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39329","https://bugzilla.redhat.com/show_bug.cgi?id=2295816"],"description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39329","epss":0.00559,"percentile":0.42836,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-39329","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-45186","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45186","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45186","epss":0.00428,"percentile":0.34702,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.321},"relatedVulnerabilities":[{"id":"CVE-2026-45186","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45186","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/pull/1216","http://www.openwall.com/lists/oss-security/2026/05/11/16","https://access.redhat.com/errata/RHSA-2026:22715","https://access.redhat.com/errata/RHSA-2026:22721","https://access.redhat.com/errata/RHSA-2026:23230","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:27201","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/security/cve/CVE-2026-45186","https://bugzilla.redhat.com/show_bug.cgi?id=2468575","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json"],"description":"In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45186","epss":0.00428,"percentile":0.34702,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-45186","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2025-69720","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00414,"percentile":0.33549,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.31671},"relatedVulnerabilities":[{"id":"CVE-2025-69720","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00414,"percentile":0.33549,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4a4ab661d3b349cf","name":"libncursesw6","version":"6.5+20250216-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libncursesw6@6.5%2B20250216-2?arch=amd64&distro=debian-13.5&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-69720","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00414,"percentile":0.33549,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.31671},"relatedVulnerabilities":[{"id":"CVE-2025-69720","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00414,"percentile":0.33549,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eb0b686927e474b5","name":"libtinfo6","version":"6.5+20250216-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64&distro=debian-13.5&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-69720","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00414,"percentile":0.33549,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.31671},"relatedVulnerabilities":[{"id":"CVE-2025-69720","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00414,"percentile":0.33549,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"}}],"artifact":{"id":"58f1158b1e8f496a","name":"ncurses-base","version":"6.5+20250216-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all&distro=debian-13.5&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-69720","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00414,"percentile":0.33549,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.31671},"relatedVulnerabilities":[{"id":"CVE-2025-69720","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00414,"percentile":0.33549,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c53b0f13a8132bdb","name":"ncurses-bin","version":"6.5+20250216-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64&distro=debian-13.5&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-14524","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14524","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14524","epss":0.00611,"percentile":0.45284,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-601","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.314665},"relatedVulnerabilities":[{"id":"CVE-2025-14524","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14524","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-14524.html","https://curl.se/docs/CVE-2025-14524.json","https://hackerone.com/reports/3459417","http://www.openwall.com/lists/oss-security/2026/01/07/4"],"description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14524","epss":0.00611,"percentile":0.45284,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-601","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14524","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-14524","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14524","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14524","epss":0.00611,"percentile":0.45284,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-601","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.314665},"relatedVulnerabilities":[{"id":"CVE-2025-14524","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14524","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-14524.html","https://curl.se/docs/CVE-2025-14524.json","https://hackerone.com/reports/3459417","http://www.openwall.com/lists/oss-security/2026/01/07/4"],"description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14524","epss":0.00611,"percentile":0.45284,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-601","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14524","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-58015","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58015","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58015","epss":0.00418,"percentile":0.33914,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3135},"relatedVulnerabilities":[{"id":"CVE-2026-58015","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-58015","https://bugzilla.redhat.com/show_bug.cgi?id=2492256","https://gitlab.gnome.org/GNOME/glib/-/issues/3931"],"description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58015","epss":0.00418,"percentile":0.33914,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glib2.0","version":"2.84.4-3~deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-58015","versionConstraint":"none (unknown)"}}],"artifact":{"id":"40a29caaab142509","name":"libglib2.0-0t64","version":"2.84.4-3~deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libglib2.0-0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0t64@2.84.4-3~deb13u3?arch=amd64&distro=debian-13.5&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-8458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8458","epss":0.00543,"percentile":0.41967,"date":"2026-07-18"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.312225},"relatedVulnerabilities":[{"id":"CVE-2026-8458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n'services'.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8458","epss":0.00543,"percentile":0.41967,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8458","epss":0.00543,"percentile":0.41967,"date":"2026-07-18"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.312225},"relatedVulnerabilities":[{"id":"CVE-2026-8458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n'services'.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8458","epss":0.00543,"percentile":0.41967,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-9545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9545","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.  When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9545","epss":0.00408,"percentile":0.33052,"date":"2026-07-18"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30600000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-9545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9545","epss":0.00408,"percentile":0.33052,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-9545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9545","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.  When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9545","epss":0.00408,"percentile":0.33052,"date":"2026-07-18"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30600000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-9545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9545","epss":0.00408,"percentile":0.33052,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.43019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.43019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.43019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.43019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.43019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.43019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.43019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.43019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.43019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.43019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-41080","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41080","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41080","epss":0.00398,"percentile":0.32109,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.2985},"relatedVulnerabilities":[{"id":"CVE-2026-41080","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41080","namespace":"nvd:cpe","severity":"High","urls":["https://blog.hartwork.org/posts/expat-2-8-0-released/","https://github.com/libexpat/libexpat/issues/47","https://github.com/libexpat/libexpat/pull/1183","https://www.openwall.com/lists/oss-security/2026/04/26/1","http://www.openwall.com/lists/oss-security/2026/04/26/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41080","epss":0.00398,"percentile":0.32109,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-41080","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2025-55780","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-55780","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-55780","epss":0.00396,"percentile":0.31892,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-55780","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.297},"relatedVulnerabilities":[{"id":"CVE-2025-55780","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55780","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708720","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=bdd5d241748807378a78a622388e0312332513c5","https://github.com/ISH2YU/CVE-2025-55780/tree/main"],"description":"A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-55780","epss":0.00396,"percentile":0.31892,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-55780","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-55780","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6de3a4b2ce25dd7","name":"libmupdf25.1","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.list"},{"path":"/var/lib/dpkg/info/libmupdf25.1.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.shlibs"},{"path":"/var/lib/dpkg/info/libmupdf25.1.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.symbols"},{"path":"/var/lib/dpkg/info/libmupdf25.1.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmupdf25.1:libmupdf25.1:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmupdf25.1@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2025-55780","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-55780","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-55780","epss":0.00396,"percentile":0.31892,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-55780","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.297},"relatedVulnerabilities":[{"id":"CVE-2025-55780","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55780","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708720","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=bdd5d241748807378a78a622388e0312332513c5","https://github.com/ISH2YU/CVE-2025-55780/tree/main"],"description":"A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-55780","epss":0.00396,"percentile":0.31892,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-55780","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-55780","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a8856e00526f091d","name":"python3-mupdf","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-mupdf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-mupdf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.list"},{"path":"/var/lib/dpkg/info/python3-mupdf.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.postinst"},{"path":"/var/lib/dpkg/info/python3-mupdf.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3-mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-mupdf@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2024-52615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00574,"percentile":0.43558,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.29561000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-52615","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00574,"percentile":0.43558,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"337bbef46c41fed2","name":"libavahi-client3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2024-52615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00574,"percentile":0.43558,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.29561000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-52615","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00574,"percentile":0.43558,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1eab38231de446ba","name":"libavahi-common-data","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2024-52615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00574,"percentile":0.43558,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.29561000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-52615","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00574,"percentile":0.43558,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eaca5e0133dcdd02","name":"libavahi-common3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1701bd9ae2c8c60","name":"fonts-opensymbol","version":"4:102.12+LibO25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/fonts-opensymbol.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/fonts-opensymbol.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/fonts-opensymbol.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/fonts-opensymbol.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:fonts-opensymbol:fonts-opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:fonts-opensymbol:fonts_opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:fonts_opensymbol:fonts-opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:fonts_opensymbol:fonts_opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:fonts:fonts-opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:fonts:fonts_opensymbol:4\\:102.12\\+LibO25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/fonts-opensymbol@4%3A102.12%2BLibO25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice%404%3A25.2.3-2%2Bdeb13u5","upstreams":[{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c4b5825229172d2b","name":"liblibreoffice-java","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblibreoffice-java.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblibreoffice-java.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblibreoffice-java.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblibreoffice-java.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblibreoffice-java:liblibreoffice-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:liblibreoffice-java:liblibreoffice_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:liblibreoffice_java:liblibreoffice-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:liblibreoffice_java:liblibreoffice_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:liblibreoffice:liblibreoffice-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:liblibreoffice:liblibreoffice_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblibreoffice-java@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"991ee90b430771d0","name":"libreoffice-base-core","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-base-core.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-core.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-base-core.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-core.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-base-core:libreoffice-base-core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base-core:libreoffice_base_core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_core:libreoffice-base-core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_core:libreoffice_base_core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice-base-core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice_base_core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice-base-core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice_base_core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-base-core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_base_core:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-base-core@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"18881d9d9f463e8b","name":"libreoffice-base-drivers","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-base-drivers.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-drivers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-base-drivers.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-drivers.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-base-drivers:libreoffice-base-drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base-drivers:libreoffice_base_drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_drivers:libreoffice-base-drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_drivers:libreoffice_base_drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice-base-drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice_base_drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice-base-drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice_base_drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-base-drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_base_drivers:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-base-drivers@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"501111a6ef4dc0d8","name":"libreoffice-base-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-base-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-base-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-base-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-base-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-base-nogui:libreoffice-base-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base-nogui:libreoffice_base_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_nogui:libreoffice-base-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base_nogui:libreoffice_base_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice-base-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-base:libreoffice_base_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice-base-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_base:libreoffice_base_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-base-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_base_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-base-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7c2f514218b3576e","name":"libreoffice-calc-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-calc-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-calc-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-calc-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-calc-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-calc-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-calc-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-calc-nogui:libreoffice-calc-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-calc-nogui:libreoffice_calc_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_calc_nogui:libreoffice-calc-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_calc_nogui:libreoffice_calc_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-calc:libreoffice-calc-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-calc:libreoffice_calc_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_calc:libreoffice-calc-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_calc:libreoffice_calc_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-calc-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_calc_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-calc-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bbefb6e067e89429","name":"libreoffice-common","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-common.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-common.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-common.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.list"},{"path":"/var/lib/dpkg/info/libreoffice-common.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.postinst"},{"path":"/var/lib/dpkg/info/libreoffice-common.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.postrm"},{"path":"/var/lib/dpkg/info/libreoffice-common.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.preinst"},{"path":"/var/lib/dpkg/info/libreoffice-common.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.prerm"},{"path":"/var/lib/dpkg/info/libreoffice-common.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-common.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-common:libreoffice-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-common:libreoffice_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_common:libreoffice-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_common:libreoffice_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-common@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d6e993d5bbfad993","name":"libreoffice-core-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-core-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-core-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-core-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-core-nogui.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-core-nogui:libreoffice-core-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-core-nogui:libreoffice_core_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_core_nogui:libreoffice-core-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_core_nogui:libreoffice_core_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-core:libreoffice-core-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-core:libreoffice_core_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_core:libreoffice-core-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_core:libreoffice_core_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-core-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_core_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-core-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"890ac2cbd45481b2","name":"libreoffice-draw-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-draw-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-draw-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-draw-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-draw-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-draw-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-draw-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-draw-nogui:libreoffice-draw-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-draw-nogui:libreoffice_draw_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_draw_nogui:libreoffice-draw-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_draw_nogui:libreoffice_draw_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-draw:libreoffice-draw-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-draw:libreoffice_draw_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_draw:libreoffice-draw-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_draw:libreoffice_draw_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-draw-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_draw_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-draw-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ee5e48d57677fd7d","name":"libreoffice-impress-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-impress-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-impress-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-impress-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-impress-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-impress-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-impress-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-impress-nogui:libreoffice-impress-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-impress-nogui:libreoffice_impress_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_impress_nogui:libreoffice-impress-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_impress_nogui:libreoffice_impress_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-impress:libreoffice-impress-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-impress:libreoffice_impress_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_impress:libreoffice-impress-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_impress:libreoffice_impress_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-impress-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_impress_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-impress-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0015e661a6b657e4","name":"libreoffice-java-common","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-java-common.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-java-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-java-common.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-java-common.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-java-common:libreoffice-java-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-java-common:libreoffice_java_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_java_common:libreoffice-java-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_java_common:libreoffice_java_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-java:libreoffice-java-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-java:libreoffice_java_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_java:libreoffice-java-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_java:libreoffice_java_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-java-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_java_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-java-common@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0b7808965ccf0eb9","name":"libreoffice-math-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-math-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-math-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-math-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-math-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-math-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-math-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-math-nogui:libreoffice-math-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-math-nogui:libreoffice_math_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_math_nogui:libreoffice-math-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_math_nogui:libreoffice_math_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-math:libreoffice-math-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-math:libreoffice_math_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_math:libreoffice-math-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_math:libreoffice_math_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-math-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_math_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-math-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c23ab5f2aa9bbf8","name":"libreoffice-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-nogui.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-nogui:libreoffice-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-nogui:libreoffice_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_nogui:libreoffice-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_nogui:libreoffice_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"065aa061da4a2271","name":"libreoffice-report-builder-bin-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-report-builder-bin-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-report-builder-bin-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-report-builder-bin-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-report-builder-bin-nogui.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-report-builder-bin-nogui:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report-builder-bin-nogui:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder_bin_nogui:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder_bin_nogui:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report-builder-bin:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report-builder-bin:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder_bin:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder_bin:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report-builder:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report-builder:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report_builder:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-report:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_report:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-report-builder-bin-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_report_builder_bin_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-report-builder-bin-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c42d0c7d012589a","name":"libreoffice-style-colibre","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-style-colibre.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-style-colibre.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-style-colibre.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-style-colibre.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-style-colibre:libreoffice-style-colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-style-colibre:libreoffice_style_colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_style_colibre:libreoffice-style-colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_style_colibre:libreoffice_style_colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-style:libreoffice-style-colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-style:libreoffice_style_colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_style:libreoffice-style-colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_style:libreoffice_style_colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-style-colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_style_colibre:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-style-colibre@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"507f67a1aba84c6f","name":"libreoffice-uiconfig-calc","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-calc.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-calc.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-calc.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-calc.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-uiconfig-calc:libreoffice-uiconfig-calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig-calc:libreoffice_uiconfig_calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_calc:libreoffice-uiconfig-calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_calc:libreoffice_uiconfig_calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice-uiconfig-calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice_uiconfig_calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice-uiconfig-calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice_uiconfig_calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-uiconfig-calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_uiconfig_calc:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-uiconfig-calc@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"86acdf8e5a25399b","name":"libreoffice-uiconfig-common","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-common.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-common.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-common.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-uiconfig-common:libreoffice-uiconfig-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig-common:libreoffice_uiconfig_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_common:libreoffice-uiconfig-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_common:libreoffice_uiconfig_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice-uiconfig-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice_uiconfig_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice-uiconfig-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice_uiconfig_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-uiconfig-common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_uiconfig_common:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-uiconfig-common@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b2d3cc35f7715bb8","name":"libreoffice-uiconfig-draw","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-draw.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-draw.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-draw.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-draw.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-uiconfig-draw:libreoffice-uiconfig-draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig-draw:libreoffice_uiconfig_draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_draw:libreoffice-uiconfig-draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_draw:libreoffice_uiconfig_draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice-uiconfig-draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice_uiconfig_draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice-uiconfig-draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice_uiconfig_draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-uiconfig-draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_uiconfig_draw:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-uiconfig-draw@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"838ef30045666ce0","name":"libreoffice-uiconfig-impress","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-impress.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-impress.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-impress.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-impress.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-uiconfig-impress:libreoffice-uiconfig-impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig-impress:libreoffice_uiconfig_impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_impress:libreoffice-uiconfig-impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_impress:libreoffice_uiconfig_impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice-uiconfig-impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice_uiconfig_impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice-uiconfig-impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice_uiconfig_impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-uiconfig-impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_uiconfig_impress:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-uiconfig-impress@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b2a463656e4e981d","name":"libreoffice-uiconfig-math","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-math.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-math.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-uiconfig-math.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-uiconfig-math.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-uiconfig-math:libreoffice-uiconfig-math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig-math:libreoffice_uiconfig_math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_math:libreoffice-uiconfig-math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig_math:libreoffice_uiconfig_math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice-uiconfig-math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-uiconfig:libreoffice_uiconfig_math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice-uiconfig-math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_uiconfig:libreoffice_uiconfig_math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-uiconfig-math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_uiconfig_math:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-uiconfig-math@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f4bdece6399f1d44","name":"libreoffice-writer-nogui","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libreoffice-writer-nogui.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-writer-nogui.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libreoffice-writer-nogui.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-writer-nogui.list"},{"path":"/var/lib/dpkg/info/libreoffice-writer-nogui.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libreoffice-writer-nogui.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libreoffice-writer-nogui:libreoffice-writer-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-writer-nogui:libreoffice_writer_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_writer_nogui:libreoffice-writer-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_writer_nogui:libreoffice_writer_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-writer:libreoffice-writer-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice-writer:libreoffice_writer_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_writer:libreoffice-writer-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice_writer:libreoffice_writer_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice-writer-nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libreoffice:libreoffice_writer_nogui:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libreoffice-writer-nogui@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f82f66b1d93b6e99","name":"libuno-cppu3t64","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuno-cppu3t64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppu3t64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuno-cppu3t64.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppu3t64.list"},{"path":"/var/lib/dpkg/info/libuno-cppu3t64.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppu3t64.shlibs"},{"path":"/var/lib/dpkg/info/libuno-cppu3t64.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppu3t64.symbols"},{"path":"/var/lib/dpkg/info/libuno-cppu3t64.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppu3t64.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuno-cppu3t64:libuno-cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-cppu3t64:libuno_cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppu3t64:libuno-cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppu3t64:libuno_cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno-cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno_cppu3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuno-cppu3t64@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"277cf190101b1d44","name":"libuno-cppuhelpergcc3-3t64","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.list"},{"path":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.shlibs"},{"path":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.symbols"},{"path":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-cppuhelpergcc3-3t64.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuno-cppuhelpergcc3-3t64:libuno-cppuhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-cppuhelpergcc3-3t64:libuno_cppuhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppuhelpergcc3_3t64:libuno-cppuhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppuhelpergcc3_3t64:libuno_cppuhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-cppuhelpergcc3:libuno-cppuhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-cppuhelpergcc3:libuno_cppuhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppuhelpergcc3:libuno-cppuhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_cppuhelpergcc3:libuno_cppuhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno-cppuhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno_cppuhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuno-cppuhelpergcc3-3t64@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bbf262193bc0b0f7","name":"libuno-purpenvhelpergcc3-3t64","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.list"},{"path":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.shlibs"},{"path":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.symbols"},{"path":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-purpenvhelpergcc3-3t64.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuno-purpenvhelpergcc3-3t64:libuno-purpenvhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-purpenvhelpergcc3-3t64:libuno_purpenvhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_purpenvhelpergcc3_3t64:libuno-purpenvhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_purpenvhelpergcc3_3t64:libuno_purpenvhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-purpenvhelpergcc3:libuno-purpenvhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-purpenvhelpergcc3:libuno_purpenvhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_purpenvhelpergcc3:libuno-purpenvhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_purpenvhelpergcc3:libuno_purpenvhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno-purpenvhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno_purpenvhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuno-purpenvhelpergcc3-3t64@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"245196f89099084f","name":"libuno-sal3t64","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuno-sal3t64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-sal3t64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuno-sal3t64.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-sal3t64.list"},{"path":"/var/lib/dpkg/info/libuno-sal3t64.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-sal3t64.shlibs"},{"path":"/var/lib/dpkg/info/libuno-sal3t64.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-sal3t64.symbols"},{"path":"/var/lib/dpkg/info/libuno-sal3t64.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-sal3t64.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuno-sal3t64:libuno-sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-sal3t64:libuno_sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_sal3t64:libuno-sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_sal3t64:libuno_sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno-sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno_sal3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuno-sal3t64@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e45d7926780dd68","name":"libuno-salhelpergcc3-3t64","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.list"},{"path":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.shlibs"},{"path":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.symbols"},{"path":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuno-salhelpergcc3-3t64.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuno-salhelpergcc3-3t64:libuno-salhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-salhelpergcc3-3t64:libuno_salhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_salhelpergcc3_3t64:libuno-salhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_salhelpergcc3_3t64:libuno_salhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-salhelpergcc3:libuno-salhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno-salhelpergcc3:libuno_salhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_salhelpergcc3:libuno-salhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno_salhelpergcc3:libuno_salhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno-salhelpergcc3-3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libuno:libuno_salhelpergcc3_3t64:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuno-salhelpergcc3-3t64@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e8e43bcf110867ce","name":"libunoloader-java","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libunoloader-java.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libunoloader-java.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libunoloader-java.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libunoloader-java.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libunoloader-java:libunoloader-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libunoloader-java:libunoloader_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libunoloader_java:libunoloader-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libunoloader_java:libunoloader_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libunoloader:libunoloader-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libunoloader:libunoloader_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libunoloader-java@4%3A25.2.3-2%2Bdeb13u5?arch=all&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b542f276d600fe07","name":"python3-uno","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-uno.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-uno.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-uno.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-uno.list"},{"path":"/var/lib/dpkg/info/python3-uno.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-uno.postinst"},{"path":"/var/lib/dpkg/info/python3-uno.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-uno.preinst"},{"path":"/var/lib/dpkg/info/python3-uno.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-uno.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-uno:python3-uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3-uno:python3_uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3_uno:python3-uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3_uno:python3_uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_uno:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-uno@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5007583eff4cae19","name":"uno-libs-private","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/uno-libs-private.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/uno-libs-private.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/uno-libs-private.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/uno-libs-private.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:uno-libs-private:uno-libs-private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno-libs-private:uno_libs_private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno_libs_private:uno-libs-private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno_libs_private:uno_libs_private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno-libs:uno-libs-private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno-libs:uno_libs_private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno_libs:uno-libs-private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno_libs:uno_libs_private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno:uno-libs-private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:uno:uno_libs_private:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/uno-libs-private@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0193eceff7def065","name":"ure","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/ure.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ure.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ure.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ure.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:ure:ure:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ure@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2012-5639","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-5639","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29185},"relatedVulnerabilities":[{"id":"CVE-2012-5639","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5639","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2012/12/14/1","http://www.openwall.com/lists/oss-security/2023/12/28/6","http://www.openwall.com/lists/oss-security/2024/01/03/6","http://www.openwall.com/lists/oss-security/2024/01/03/7","https://access.redhat.com/security/cve/cve-2012-5639","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639","https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-5639"],"description":"LibreOffice and OpenOffice automatically open embedded content","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-5639","epss":0.05837,"percentile":0.92342,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-5639","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libreoffice","version":"4:25.2.3-2+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-5639","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9a05e0f5aa69cb96","name":"ure-java","version":"4:25.2.3-2+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/ure-java.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ure-java.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ure-java.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ure-java.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:ure-java:ure-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:ure-java:ure_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:ure_java:ure-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:ure_java:ure_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:ure:ure-java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:ure:ure_java:4\\:25.2.3-2\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ure-java@4%3A25.2.3-2%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libreoffice","upstreams":[{"name":"libreoffice"}]}},{"vulnerability":{"id":"CVE-2018-20796","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[],"epss":[{"cve":"CVE-2018-20796","epss":0.05804,"percentile":0.92297,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.2902},"relatedVulnerabilities":[{"id":"CVE-2018-20796","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20796","epss":0.05804,"percentile":0.92297,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1ded7e36f657ba6e","name":"libc-bin","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2018-20796","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[],"epss":[{"cve":"CVE-2018-20796","epss":0.05804,"percentile":0.92297,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.2902},"relatedVulnerabilities":[{"id":"CVE-2018-20796","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20796","epss":0.05804,"percentile":0.92297,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1e14850bd315eb8f","name":"libc6","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00492,"percentile":0.39031,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.27798},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00492,"percentile":0.39031,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00492,"percentile":0.39031,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.27798},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00492,"percentile":0.39031,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00492,"percentile":0.39031,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.27798},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00492,"percentile":0.39031,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00492,"percentile":0.39031,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.27798},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00492,"percentile":0.39031,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00492,"percentile":0.39031,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.27798},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00492,"percentile":0.39031,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-5928","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.29164,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27675},"relatedVulnerabilities":[{"id":"CVE-2026-5928","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.29164,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1ded7e36f657ba6e","name":"libc-bin","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5928","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.29164,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27675},"relatedVulnerabilities":[{"id":"CVE-2026-5928","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.29164,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1e14850bd315eb8f","name":"libc6","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-8932","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8932","epss":0.00368,"percentile":0.29034,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.276},"relatedVulnerabilities":[{"id":"CVE-2026-8932","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8932","epss":0.00368,"percentile":0.29034,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8932","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8932","epss":0.00368,"percentile":0.29034,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.276},"relatedVulnerabilities":[{"id":"CVE-2026-8932","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8932","epss":0.00368,"percentile":0.29034,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-6429","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6429","epss":0.00519,"percentile":0.40669,"date":"2026-07-18"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.267285},"relatedVulnerabilities":[{"id":"CVE-2026-6429","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6429","epss":0.00519,"percentile":0.40669,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-6429","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6429","epss":0.00519,"percentile":0.40669,"date":"2026-07-18"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.267285},"relatedVulnerabilities":[{"id":"CVE-2026-6429","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6429","epss":0.00519,"percentile":0.40669,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2015-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-3276","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.","cvss":[],"epss":[{"cve":"CVE-2015-3276","epss":0.05333,"percentile":0.9171,"date":"2026-07-18"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26665000000000005},"relatedVulnerabilities":[{"id":"CVE-2015-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3276","namespace":"nvd:cpe","severity":"High","urls":["http://rhn.redhat.com/errata/RHSA-2015-2131.html","http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","http://www.securitytracker.com/id/1034221","https://bugzilla.redhat.com/show_bug.cgi?id=1238322"],"description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-3276","epss":0.05333,"percentile":0.9171,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2015-3276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34614e72922d8e4b","name":"libldap2","version":"2.6.10+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.5&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00513,"percentile":0.40282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.264195},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00513,"percentile":0.40282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00513,"percentile":0.40282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.264195},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00513,"percentile":0.40282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00513,"percentile":0.40282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.264195},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00513,"percentile":0.40282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00513,"percentile":0.40282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.264195},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00513,"percentile":0.40282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00513,"percentile":0.40282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.264195},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00513,"percentile":0.40282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00476,"percentile":0.38035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.25942000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00476,"percentile":0.38035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00476,"percentile":0.38035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.25942000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00476,"percentile":0.38035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00476,"percentile":0.38035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.25942000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00476,"percentile":0.38035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00476,"percentile":0.38035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.25942000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00476,"percentile":0.38035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00476,"percentile":0.38035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":["3.13.5-2+deb13u3"],"state":"fixed","available":[{"version":"3.13.5-2+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.25942000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00476,"percentile":0.38035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.13.5-2+deb13u3 (deb)"},"fix":{"suggestedVersion":"3.13.5-2+deb13u3"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-58013","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58013","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58013","epss":0.00329,"percentile":0.25069,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.25826499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-58013","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58013","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-58013","https://bugzilla.redhat.com/show_bug.cgi?id=2492248","https://gitlab.gnome.org/GNOME/glib/-/issues/3925"],"description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58013","epss":0.00329,"percentile":0.25069,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glib2.0","version":"2.84.4-3~deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-58013","versionConstraint":"none (unknown)"}}],"artifact":{"id":"40a29caaab142509","name":"libglib2.0-0t64","version":"2.84.4-3~deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libglib2.0-0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0t64@2.84.4-3~deb13u3?arch=amd64&distro=debian-13.5&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58011","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58011","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58011","epss":0.00344,"percentile":0.2661,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.258},"relatedVulnerabilities":[{"id":"CVE-2026-58011","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58011","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-58011","https://bugzilla.redhat.com/show_bug.cgi?id=2492245","https://gitlab.gnome.org/GNOME/glib/-/issues/3917","https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"],"description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58011","epss":0.00344,"percentile":0.2661,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glib2.0","version":"2.84.4-3~deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-58011","versionConstraint":"none (unknown)"}}],"artifact":{"id":"40a29caaab142509","name":"libglib2.0-0t64","version":"2.84.4-3~deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libglib2.0-0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0t64@2.84.4-3~deb13u3?arch=amd64&distro=debian-13.5&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58012","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58012","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58012","epss":0.00322,"percentile":0.24352,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.25277},"relatedVulnerabilities":[{"id":"CVE-2026-58012","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58012","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-58012","https://bugzilla.redhat.com/show_bug.cgi?id=2492247","https://gitlab.gnome.org/GNOME/glib/-/issues/3918"],"description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58012","epss":0.00322,"percentile":0.24352,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glib2.0","version":"2.84.4-3~deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-58012","versionConstraint":"none (unknown)"}}],"artifact":{"id":"40a29caaab142509","name":"libglib2.0-0t64","version":"2.84.4-3~deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libglib2.0-0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0t64@2.84.4-3~deb13u3?arch=amd64&distro=debian-13.5&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58010","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58010","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58010","epss":0.00322,"percentile":0.24351,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.25277},"relatedVulnerabilities":[{"id":"CVE-2026-58010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58010","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-58010","https://bugzilla.redhat.com/show_bug.cgi?id=2492243","https://gitlab.gnome.org/GNOME/glib/-/issues/3915"],"description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58010","epss":0.00322,"percentile":0.24351,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glib2.0","version":"2.84.4-3~deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-58010","versionConstraint":"none (unknown)"}}],"artifact":{"id":"40a29caaab142509","name":"libglib2.0-0t64","version":"2.84.4-3~deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libglib2.0-0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0t64@2.84.4-3~deb13u3?arch=amd64&distro=debian-13.5&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2023-39327","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39327","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39327","epss":0.00528,"percentile":0.41121,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24552},"relatedVulnerabilities":[{"id":"CVE-2023-39327","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39327","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39327","https://bugzilla.redhat.com/show_bug.cgi?id=2295812"],"description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39327","epss":0.00528,"percentile":0.41121,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-39327","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-7168","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7168","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for `proxyA`, to `proxyB`.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7168","epss":0.00471,"percentile":0.37742,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.242565},"relatedVulnerabilities":[{"id":"CVE-2026-7168","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7168","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-7168.html","https://curl.se/docs/CVE-2026-7168.json","https://hackerone.com/reports/3697719","http://www.openwall.com/lists/oss-security/2026/04/29/14"],"description":"Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7168","epss":0.00471,"percentile":0.37742,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7168","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-7168","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7168","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for `proxyA`, to `proxyB`.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7168","epss":0.00471,"percentile":0.37742,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.242565},"relatedVulnerabilities":[{"id":"CVE-2026-7168","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7168","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-7168.html","https://curl.se/docs/CVE-2026-7168.json","https://hackerone.com/reports/3697719","http://www.openwall.com/lists/oss-security/2026/04/29/14"],"description":"Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7168","epss":0.00471,"percentile":0.37742,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7168","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2017-16232","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-16232","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue","cvss":[],"epss":[{"cve":"CVE-2017-16232","epss":0.04766,"percentile":0.90904,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.2383},"relatedVulnerabilities":[{"id":"CVE-2017-16232","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-16232","namespace":"nvd:cpe","severity":"High","urls":["http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00036.html","http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00041.html","http://packetstormsecurity.com/files/150896/LibTIFF-4.0.8-Memory-Leak.html","http://seclists.org/fulldisclosure/2018/Dec/32","http://seclists.org/fulldisclosure/2018/Dec/47","http://www.openwall.com/lists/oss-security/2017/11/01/11","http://www.openwall.com/lists/oss-security/2017/11/01/3","http://www.openwall.com/lists/oss-security/2017/11/01/7","http://www.openwall.com/lists/oss-security/2017/11/01/8","http://www.securityfocus.com/bid/101696"],"description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-16232","epss":0.04766,"percentile":0.90904,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tiff","version":"4.7.0-3+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-16232","versionConstraint":"none (unknown)"}}],"artifact":{"id":"632b90e0e50cde2d","name":"libtiff6","version":"4.7.0-3+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-5545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5545","epss":0.00414,"percentile":0.33545,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-613","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.23804999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-5545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5545","epss":0.00414,"percentile":0.33545,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-613","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-5545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5545","epss":0.00414,"percentile":0.33545,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-613","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.23804999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-5545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5545","epss":0.00414,"percentile":0.33545,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-613","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-58014","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58014","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58014","epss":0.00293,"percentile":0.21198,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.235865},"relatedVulnerabilities":[{"id":"CVE-2026-58014","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58014","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-58014","https://bugzilla.redhat.com/show_bug.cgi?id=2492255","https://gitlab.gnome.org/GNOME/glib/-/issues/3930"],"description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58014","epss":0.00293,"percentile":0.21198,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glib2.0","version":"2.84.4-3~deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-58014","versionConstraint":"none (unknown)"}}],"artifact":{"id":"40a29caaab142509","name":"libglib2.0-0t64","version":"2.84.4-3~deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libglib2.0-0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0t64@2.84.4-3~deb13u3?arch=amd64&distro=debian-13.5&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2025-71382","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71382","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in css-apply.c recurses through the CSS property inheritance chain without a depth limit, exhausting the process stack and causing a crash in any application using MuPDF for EPUB rendering.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71382","epss":0.00316,"percentile":0.23595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-71382","cwe":"CWE-674","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.23068},"relatedVulnerabilities":[{"id":"CVE-2025-71382","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71382","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708840","https://github.com/ArtifexSoftware/mupdf/commit/70b71ab22e6de4d4c44cd301c88231f623a4e94e","https://github.com/ArtifexSoftware/mupdf/releases/tag/1.27.0-rc1","https://www.vulncheck.com/advisories/mupdf-rc1-stack-exhaustion-dos-via-epub-css-rendering"],"description":"MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in css-apply.c recurses through the CSS property inheritance chain without a depth limit, exhausting the process stack and causing a crash in any application using MuPDF for EPUB rendering.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71382","epss":0.00316,"percentile":0.23595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-71382","cwe":"CWE-674","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-71382","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6de3a4b2ce25dd7","name":"libmupdf25.1","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.list"},{"path":"/var/lib/dpkg/info/libmupdf25.1.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.shlibs"},{"path":"/var/lib/dpkg/info/libmupdf25.1.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.symbols"},{"path":"/var/lib/dpkg/info/libmupdf25.1.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmupdf25.1:libmupdf25.1:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmupdf25.1@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2025-71382","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71382","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in css-apply.c recurses through the CSS property inheritance chain without a depth limit, exhausting the process stack and causing a crash in any application using MuPDF for EPUB rendering.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71382","epss":0.00316,"percentile":0.23595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-71382","cwe":"CWE-674","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.23068},"relatedVulnerabilities":[{"id":"CVE-2025-71382","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71382","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708840","https://github.com/ArtifexSoftware/mupdf/commit/70b71ab22e6de4d4c44cd301c88231f623a4e94e","https://github.com/ArtifexSoftware/mupdf/releases/tag/1.27.0-rc1","https://www.vulncheck.com/advisories/mupdf-rc1-stack-exhaustion-dos-via-epub-css-rendering"],"description":"MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in css-apply.c recurses through the CSS property inheritance chain without a depth limit, exhausting the process stack and causing a crash in any application using MuPDF for EPUB rendering.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71382","epss":0.00316,"percentile":0.23595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-71382","cwe":"CWE-674","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-71382","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a8856e00526f091d","name":"python3-mupdf","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-mupdf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-mupdf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.list"},{"path":"/var/lib/dpkg/info/python3-mupdf.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.postinst"},{"path":"/var/lib/dpkg/info/python3-mupdf.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3-mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-mupdf@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2026-5704","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5704","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5704","epss":0.0043,"percentile":0.34873,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22575},"relatedVulnerabilities":[{"id":"CVE-2026-5704","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5704","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-5704","https://bugzilla.redhat.com/show_bug.cgi?id=2455360","http://www.openwall.com/lists/oss-security/2026/04/11/10","http://www.openwall.com/lists/oss-security/2026/04/11/11","http://www.openwall.com/lists/oss-security/2026/04/12/2"],"description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5704","epss":0.0043,"percentile":0.34873,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-5704","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4e59b3623bd2da47","name":"tar","version":"1.35+dfsg-3.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"943eceb0b62d5077","name":"bsdutils","version":"1:2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"789c9c1c32d67963","name":"libblkid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1c14db01751ab35","name":"liblastlog2-2","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f2906fa44fcde82e","name":"libmount1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6bc0f11ba93c58e0","name":"libsmartcols1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b9befafdeaa440fd","name":"libuuid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dc55662712ce7274","name":"login","version":"1:4.16.0-2+really2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0adc54d0e11f3b69","name":"mount","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.3537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3accc11c0ad101fe","name":"util-linux","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-46206","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-46206","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-46206","epss":0.00384,"percentile":0.30724,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-46206","cwe":"CWE-674","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.2208},"relatedVulnerabilities":[{"id":"CVE-2025-46206","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-46206","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708521","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=0ec7e4d2201bb6df217e01c17396d36297abf9ac","https://github.com/Landw-hub/CVE-2025-46206"],"description":"An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-46206","epss":0.00384,"percentile":0.30724,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-46206","cwe":"CWE-674","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-46206","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6de3a4b2ce25dd7","name":"libmupdf25.1","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.list"},{"path":"/var/lib/dpkg/info/libmupdf25.1.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.shlibs"},{"path":"/var/lib/dpkg/info/libmupdf25.1.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.symbols"},{"path":"/var/lib/dpkg/info/libmupdf25.1.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmupdf25.1:libmupdf25.1:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmupdf25.1@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2025-46206","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-46206","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-46206","epss":0.00384,"percentile":0.30724,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-46206","cwe":"CWE-674","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.2208},"relatedVulnerabilities":[{"id":"CVE-2025-46206","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-46206","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708521","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=0ec7e4d2201bb6df217e01c17396d36297abf9ac","https://github.com/Landw-hub/CVE-2025-46206"],"description":"An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-46206","epss":0.00384,"percentile":0.30724,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-46206","cwe":"CWE-674","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-46206","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a8856e00526f091d","name":"python3-mupdf","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-mupdf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-mupdf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.list"},{"path":"/var/lib/dpkg/info/python3-mupdf.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.postinst"},{"path":"/var/lib/dpkg/info/python3-mupdf.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3-mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-mupdf@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2017-2820","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-2820","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary code execution. To trigger this vulnerability, a victim must open the malicious PDF in an application using this library.","cvss":[],"epss":[{"cve":"CVE-2017-2820","epss":0.04415,"percentile":0.90272,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-2820","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22075000000000003},"relatedVulnerabilities":[{"id":"CVE-2017-2820","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-2820","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/99497","https://talosintelligence.com/vulnerability_reports/TALOS-2017-0321"],"description":"An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary code execution. To trigger this vulnerability, a victim must open the malicious PDF in an application using this library.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"talos-cna@cisco.com","type":"Secondary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-2820","epss":0.04415,"percentile":0.90272,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-2820","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"poppler","version":"25.03.0-5+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-2820","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f9378ee2c5fb55fb","name":"libpoppler147","version":"25.03.0-5+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpoppler147:libpoppler147:25.03.0-5\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpoppler147@25.03.0-5%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=poppler","upstreams":[{"name":"poppler"}]}},{"vulnerability":{"id":"CVE-2026-41992","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41992","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.  This issue has been fixed in the commit 63dbf6b3b9e6e781df1a6a64e609b10e23969681","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41992","epss":0.00294,"percentile":0.21376,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.2205},"relatedVulnerabilities":[{"id":"CVE-2026-41992","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41992","namespace":"nvd:cpe","severity":"High","urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681","https://www.gnu.org/software/gzip/"],"description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in the commit 63dbf6b3b9e6e781df1a6a64e609b10e23969681","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41992","epss":0.00294,"percentile":0.21376,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gzip","version":"1.13-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-41992","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c921f12dfe29d361","name":"gzip","version":"1.13-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gzip.list"},{"path":"/var/lib/dpkg/info/gzip.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gzip.postinst"},{"path":"/var/lib/dpkg/info/gzip.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gzip.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gzip:gzip:1.13-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gzip@1.13-1?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6276","epss":0.00291,"percentile":0.21005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-319","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.21825},"relatedVulnerabilities":[{"id":"CVE-2026-6276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6276","epss":0.00291,"percentile":0.21005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-319","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-6276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6276","epss":0.00291,"percentile":0.21005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-319","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.21825},"relatedVulnerabilities":[{"id":"CVE-2026-6276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6276","epss":0.00291,"percentile":0.21005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-319","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-6238","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.28095,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20584999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-6238","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","namespace":"nvd:cpe","severity":"Medium","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.28095,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1ded7e36f657ba6e","name":"libc-bin","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6238","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.28095,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20584999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-6238","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","namespace":"nvd:cpe","severity":"Medium","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.28095,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1e14850bd315eb8f","name":"libc6","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2025-68471","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00353,"percentile":0.27585,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.202975},"relatedVulnerabilities":[{"id":"CVE-2025-68471","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00353,"percentile":0.27585,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"}}],"artifact":{"id":"337bbef46c41fed2","name":"libavahi-client3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68471","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00353,"percentile":0.27585,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.202975},"relatedVulnerabilities":[{"id":"CVE-2025-68471","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00353,"percentile":0.27585,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1eab38231de446ba","name":"libavahi-common-data","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68471","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00353,"percentile":0.27585,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.202975},"relatedVulnerabilities":[{"id":"CVE-2025-68471","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00353,"percentile":0.27585,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eaca5e0133dcdd02","name":"libavahi-common3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2005-2541","dataSource":"https://security-tracker.debian.org/tracker/CVE-2005-2541","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.","cvss":[],"epss":[{"cve":"CVE-2005-2541","epss":0.03992,"percentile":0.89371,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1996},"relatedVulnerabilities":[{"id":"CVE-2005-2541","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2005-2541","namespace":"nvd:cpe","severity":"High","urls":["http://marc.info/?l=bugtraq&m=112327628230258&w=2","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E"],"description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"exploitabilityScore":10,"impactScore":10.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2005-2541","epss":0.03992,"percentile":0.89371,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2005-2541","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4e59b3623bd2da47","name":"tar","version":"1.35+dfsg-3.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-54411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.00333,"percentile":0.25462,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.19813499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-54411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","namespace":"nvd:cpe","severity":"Medium","urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}},{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.00333,"percentile":0.25462,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d77b42b14067c716","name":"libpam-modules","version":"1.7.0-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.7.0-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-modules@1.7.0-5?arch=amd64&distro=debian-13.5&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"CVE-2026-54411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.00333,"percentile":0.25462,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.19813499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-54411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","namespace":"nvd:cpe","severity":"Medium","urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}},{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.00333,"percentile":0.25462,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e43c6da1c40c37d2","name":"libpam-modules-bin","version":"1.7.0-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-modules-bin@1.7.0-5?arch=amd64&distro=debian-13.5&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"CVE-2026-54411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.00333,"percentile":0.25462,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.19813499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-54411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","namespace":"nvd:cpe","severity":"Medium","urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}},{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.00333,"percentile":0.25462,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2fc4c2e2f4654a79","name":"libpam-runtime","version":"1.7.0-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-runtime@1.7.0-5?arch=all&distro=debian-13.5&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"CVE-2026-54411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.00333,"percentile":0.25462,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.19813499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-54411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","namespace":"nvd:cpe","severity":"Medium","urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}},{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.00333,"percentile":0.25462,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"}}],"artifact":{"id":"48356a1e1d90c04b","name":"libpam0g","version":"1.7.0-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpam0g:libpam0g:1.7.0-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam0g@1.7.0-5?arch=amd64&distro=debian-13.5&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.0036,"percentile":0.28282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1962},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.0036,"percentile":0.28282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.0036,"percentile":0.28282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1962},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.0036,"percentile":0.28282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.0036,"percentile":0.28282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1962},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.0036,"percentile":0.28282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.0036,"percentile":0.28282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1962},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.0036,"percentile":0.28282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.0036,"percentile":0.28282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1962},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.0036,"percentile":0.28282,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-12318","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12318","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12318","epss":0.00263,"percentile":0.17864,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12318","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["2:3.110-1+deb13u3"],"state":"fixed","available":[{"version":"2:3.110-1+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.19462},"relatedVulnerabilities":[{"id":"CVE-2026-12318","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12318","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2023478","https://www.mozilla.org/security/advisories/mfsa2026-57/","https://www.mozilla.org/security/advisories/mfsa2026-60/"],"description":"Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12318","epss":0.00263,"percentile":0.17864,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12318","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"nss","version":"2:3.110-1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-12318","versionConstraint":"< 2:3.110-1+deb13u3 (deb)"},"fix":{"suggestedVersion":"2:3.110-1+deb13u3"}}],"artifact":{"id":"d66110c0ae26fe8f","name":"libnss3","version":"2:3.110-1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.110-1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.110-1%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2025-68468","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00331,"percentile":0.25281,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.19032499999999997},"relatedVulnerabilities":[{"id":"CVE-2025-68468","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00331,"percentile":0.25281,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"}}],"artifact":{"id":"337bbef46c41fed2","name":"libavahi-client3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68468","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00331,"percentile":0.25281,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.19032499999999997},"relatedVulnerabilities":[{"id":"CVE-2025-68468","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00331,"percentile":0.25281,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1eab38231de446ba","name":"libavahi-common-data","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68468","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00331,"percentile":0.25281,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.19032499999999997},"relatedVulnerabilities":[{"id":"CVE-2025-68468","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00331,"percentile":0.25281,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eaca5e0133dcdd02","name":"libavahi-common3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-34743","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34743","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34743","epss":0.00351,"percentile":0.2742,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["5.8.1-1+deb13u1"],"state":"fixed","available":[{"version":"5.8.1-1+deb13u1","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.180765},"relatedVulnerabilities":[{"id":"CVE-2026-34743","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34743","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87","https://github.com/tukaani-project/xz/releases/tag/v5.8.3","https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv","http://www.openwall.com/lists/oss-security/2026/03/31/13"],"description":"XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34743","epss":0.00351,"percentile":0.2742,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"xz-utils","version":"5.8.1-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-34743","versionConstraint":"< 5.8.1-1+deb13u1 (deb)"},"fix":{"suggestedVersion":"5.8.1-1+deb13u1"}}],"artifact":{"id":"39f019b7a27eff9a","name":"liblzma5","version":"5.8.1-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblzma5:liblzma5:5.8.1-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblzma5@5.8.1-1?arch=amd64&distro=debian-13.5&upstream=xz-utils","upstreams":[{"name":"xz-utils"}]}},{"vulnerability":{"id":"CVE-2026-4873","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4873","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4873","epss":0.00329,"percentile":0.25014,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-4873","cwe":"CWE-319","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.179305},"relatedVulnerabilities":[{"id":"CVE-2026-4873","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4873","epss":0.00329,"percentile":0.25014,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-4873","cwe":"CWE-319","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-4873","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-4873","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4873","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4873","epss":0.00329,"percentile":0.25014,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-4873","cwe":"CWE-319","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.179305},"relatedVulnerabilities":[{"id":"CVE-2026-4873","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4873","epss":0.00329,"percentile":0.25014,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-4873","cwe":"CWE-319","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-4873","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-5435","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14671,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17538},"relatedVulnerabilities":[{"id":"CVE-2026-5435","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","namespace":"nvd:cpe","severity":"High","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14671,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1ded7e36f657ba6e","name":"libc-bin","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5435","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14671,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17538},"relatedVulnerabilities":[{"id":"CVE-2026-5435","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","namespace":"nvd:cpe","severity":"High","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14671,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1e14850bd315eb8f","name":"libc6","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-3784","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3784","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3784","epss":0.00302,"percentile":0.22115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.17365},"relatedVulnerabilities":[{"id":"CVE-2026-3784","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3784","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-3784.html","https://curl.se/docs/CVE-2026-3784.json","https://hackerone.com/reports/3584903","http://www.openwall.com/lists/oss-security/2026/03/11/3","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3784","epss":0.00302,"percentile":0.22115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3784","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-3784","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3784","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3784","epss":0.00302,"percentile":0.22115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.17365},"relatedVulnerabilities":[{"id":"CVE-2026-3784","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3784","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-3784.html","https://curl.se/docs/CVE-2026-3784.json","https://hackerone.com/reports/3584903","http://www.openwall.com/lists/oss-security/2026/03/11/3","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3784","epss":0.00302,"percentile":0.22115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3784","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00315,"percentile":0.23523,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17167500000000002},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00315,"percentile":0.23523,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00315,"percentile":0.23523,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17167500000000002},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00315,"percentile":0.23523,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00315,"percentile":0.23523,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17167500000000002},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00315,"percentile":0.23523,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00315,"percentile":0.23523,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17167500000000002},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00315,"percentile":0.23523,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00315,"percentile":0.23523,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17167500000000002},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00315,"percentile":0.23523,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-3783","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3783","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances.  If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `default` keywords, curl would pass on the bearer token set for the first host also to the second one.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3783","epss":0.00333,"percentile":0.25471,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.171495},"relatedVulnerabilities":[{"id":"CVE-2026-3783","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3783","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-3783.html","https://curl.se/docs/CVE-2026-3783.json","https://hackerone.com/reports/3583983","http://www.openwall.com/lists/oss-security/2026/03/11/2"],"description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3783","epss":0.00333,"percentile":0.25471,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3783","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-3783","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3783","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances.  If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `default` keywords, curl would pass on the bearer token set for the first host also to the second one.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3783","epss":0.00333,"percentile":0.25471,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.171495},"relatedVulnerabilities":[{"id":"CVE-2026-3783","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3783","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-3783.html","https://curl.se/docs/CVE-2026-3783.json","https://hackerone.com/reports/3583983","http://www.openwall.com/lists/oss-security/2026/03/11/2"],"description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3783","epss":0.00333,"percentile":0.25471,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3783","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-12912","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12912","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.4,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12912","epss":0.00231,"percentile":0.13967,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-12912","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17094},"relatedVulnerabilities":[{"id":"CVE-2026-12912","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12912","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:34890","https://access.redhat.com/security/cve/CVE-2026-12912","https://bugzilla.redhat.com/show_bug.cgi?id=2492871","https://gitlab.com/libtiff/libtiff/-/merge_requests/873","https://gitlab.com/libtiff/libtiff/-/work_items/824","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12912.json"],"description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.4,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.4,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12912","epss":0.00231,"percentile":0.13967,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-12912","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tiff","version":"4.7.0-3+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-12912","versionConstraint":"none (unknown)"}}],"artifact":{"id":"632b90e0e50cde2d","name":"libtiff6","version":"4.7.0-3+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2019-1010022","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010022","epss":0.03249,"percentile":0.86933,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16245},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","namespace":"nvd:cpe","severity":"Critical","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010022","epss":0.03249,"percentile":0.86933,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1ded7e36f657ba6e","name":"libc-bin","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010022","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010022","epss":0.03249,"percentile":0.86933,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16245},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","namespace":"nvd:cpe","severity":"Critical","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010022","epss":0.03249,"percentile":0.86933,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1e14850bd315eb8f","name":"libc6","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010024","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010024","epss":0.0322,"percentile":0.86803,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.161},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010024","epss":0.0322,"percentile":0.86803,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1ded7e36f657ba6e","name":"libc-bin","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010024","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010024","epss":0.0322,"percentile":0.86803,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.161},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010024","epss":0.0322,"percentile":0.86803,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1e14850bd315eb8f","name":"libc6","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2016-9114","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9114","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.","cvss":[],"epss":[{"cve":"CVE-2016-9114","epss":0.03077,"percentile":0.86193,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9114","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15385},"relatedVulnerabilities":[{"id":"CVE-2016-9114","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9114","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/93979","https://github.com/uclouvain/openjpeg/issues/857","https://security.gentoo.org/glsa/201710-26"],"description":"There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9114","epss":0.03077,"percentile":0.86193,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9114","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2016-9114","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2019-1010023","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010023","epss":0.03069,"percentile":0.86161,"date":"2026-07-18"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15345},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","epss":0.03069,"percentile":0.86161,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1ded7e36f657ba6e","name":"libc-bin","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010023","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010023","epss":0.03069,"percentile":0.86161,"date":"2026-07-18"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15345},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","epss":0.03069,"percentile":0.86161,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1e14850bd315eb8f","name":"libc6","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2016-9113","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9113","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service.","cvss":[],"epss":[{"cve":"CVE-2016-9113","epss":0.0305,"percentile":0.86082,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9113","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1525},"relatedVulnerabilities":[{"id":"CVE-2016-9113","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9113","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/93980","https://github.com/uclouvain/openjpeg/issues/856","https://security.gentoo.org/glsa/201710-26"],"description":"There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9113","epss":0.0305,"percentile":0.86082,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9113","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2016-9113","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-1965","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1965","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work.  An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it just sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1...  The set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.  Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1965","epss":0.00259,"percentile":0.17413,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.148925},"relatedVulnerabilities":[{"id":"CVE-2026-1965","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1965","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-1965.html","https://curl.se/docs/CVE-2026-1965.json"],"description":"libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1965","epss":0.00259,"percentile":0.17413,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-1965","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-1965","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1965","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work.  An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it just sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1...  The set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.  Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1965","epss":0.00259,"percentile":0.17413,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["8.14.1-2+deb13u4"],"state":"fixed","available":[{"version":"8.14.1-2+deb13u4","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.148925},"relatedVulnerabilities":[{"id":"CVE-2026-1965","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1965","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-1965.html","https://curl.se/docs/CVE-2026-1965.json"],"description":"libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1965","epss":0.00259,"percentile":0.17413,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-1965","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"fix":{"suggestedVersion":"8.14.1-2+deb13u4"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-25210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-25210","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25210","epss":0.00193,"percentile":0.091,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-25210","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.147645},"relatedVulnerabilities":[{"id":"CVE-2026-25210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/pull/1075","https://github.com/libexpat/libexpat/pull/1075/commits/9c2d990389e6abe2e44527eeaa8b39f16fe859c7","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25210","epss":0.00193,"percentile":0.091,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-25210","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-25210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-24401","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24401","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00252,"percentile":0.16535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1449},"relatedVulnerabilities":[{"id":"CVE-2026-24401","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24401","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524","https://github.com/avahi/avahi/issues/501","https://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00252,"percentile":0.16535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-24401","versionConstraint":"none (unknown)"}}],"artifact":{"id":"337bbef46c41fed2","name":"libavahi-client3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-24401","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24401","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00252,"percentile":0.16535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1449},"relatedVulnerabilities":[{"id":"CVE-2026-24401","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24401","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524","https://github.com/avahi/avahi/issues/501","https://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00252,"percentile":0.16535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-24401","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1eab38231de446ba","name":"libavahi-common-data","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-24401","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24401","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00252,"percentile":0.16535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1449},"relatedVulnerabilities":[{"id":"CVE-2026-24401","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24401","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524","https://github.com/avahi/avahi/issues/501","https://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00252,"percentile":0.16535,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-24401","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eaca5e0133dcdd02","name":"libavahi-common3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2017-9937","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-9937","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.","cvss":[],"epss":[{"cve":"CVE-2017-9937","epss":0.02846,"percentile":0.85123,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-9937","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1423},"relatedVulnerabilities":[{"id":"CVE-2017-9937","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9937","namespace":"nvd:cpe","severity":"Medium","urls":["http://bugzilla.maptools.org/show_bug.cgi?id=2707","http://www.securityfocus.com/bid/99304","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-9937","epss":0.02846,"percentile":0.85123,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-9937","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"jbigkit","version":"2.1-6.1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-9937","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b552173cb163bf9b","name":"libjbig0","version":"2.1-6.1+b2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libjbig0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libjbig0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libjbig0:libjbig0:2.1-6.1\\+b2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjbig0@2.1-6.1%2Bb2?arch=amd64&distro=debian-13.5&upstream=jbigkit%402.1-6.1","upstreams":[{"name":"jbigkit","version":"2.1-6.1"}]}},{"vulnerability":{"id":"CVE-2026-0989","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0989","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0989","epss":0.00419,"percentile":0.34034,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0989","cwe":"CWE-674","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":["2.12.7+dfsg+really2.9.14-2.1+deb13u3"],"state":"fixed","available":[{"version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.140365},"relatedVulnerabilities":[{"id":"CVE-2026-0989","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0989","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-0989","https://bugzilla.redhat.com/show_bug.cgi?id=2429933","https://gitlab.gnome.org/GNOME/libxml2/-/issues/998"],"description":"A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0989","epss":0.00419,"percentile":0.34034,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0989","cwe":"CWE-674","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-0989","versionConstraint":"< 2.12.7+dfsg+really2.9.14-2.1+deb13u3 (deb)"},"fix":{"suggestedVersion":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"}}],"artifact":{"id":"07fee9125970d2ca","name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2017-2814","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-2814","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation has already occurred, resulting in heap corruption which can lead to code execution. An attacker controlled PDF file can be used to trigger this vulnerability.","cvss":[],"epss":[{"cve":"CVE-2017-2814","epss":0.02716,"percentile":0.84359,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-2814","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1358},"relatedVulnerabilities":[{"id":"CVE-2017-2814","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-2814","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/99497","https://talosintelligence.com/vulnerability_reports/TALOS-2017-0311"],"description":"An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation has already occurred, resulting in heap corruption which can lead to code execution. An attacker controlled PDF file can be used to trigger this vulnerability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"talos-cna@cisco.com","type":"Secondary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-2814","epss":0.02716,"percentile":0.84359,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-2814","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"poppler","version":"25.03.0-5+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-2814","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f9378ee2c5fb55fb","name":"libpoppler147","version":"25.03.0-5+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpoppler147:libpoppler147:25.03.0-5\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpoppler147@25.03.0-5%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=poppler","upstreams":[{"name":"poppler"}]}},{"vulnerability":{"id":"CVE-2018-16376","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-16376","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.","cvss":[],"epss":[{"cve":"CVE-2018-16376","epss":0.02647,"percentile":0.83916,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-16376","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13235},"relatedVulnerabilities":[{"id":"CVE-2018-16376","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16376","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/105262","https://github.com/uclouvain/openjpeg/issues/1127"],"description":"An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-16376","epss":0.02647,"percentile":0.83916,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-16376","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-16376","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-7233","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7233","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7233","epss":0.00238,"percentile":0.14764,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7233","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-7233","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.13208999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-7233","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7233","namespace":"nvd:cpe","severity":"Medium","urls":["https://artifex.com/","https://bugs.ghostscript.com/show_bug.cgi?id=709328","https://github.com/biniamf/pocs/tree/main/mupdf-cff-indexload-oobread","https://vuldb.com/submit/802590","https://vuldb.com/vuln/359840","https://vuldb.com/vuln/359840/cti"],"description":"A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:N/A:N","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7233","epss":0.00238,"percentile":0.14764,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7233","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-7233","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7233","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6de3a4b2ce25dd7","name":"libmupdf25.1","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.list"},{"path":"/var/lib/dpkg/info/libmupdf25.1.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.shlibs"},{"path":"/var/lib/dpkg/info/libmupdf25.1.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.symbols"},{"path":"/var/lib/dpkg/info/libmupdf25.1.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmupdf25.1:libmupdf25.1:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmupdf25.1@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2026-7233","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7233","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7233","epss":0.00238,"percentile":0.14764,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7233","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-7233","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.13208999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-7233","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7233","namespace":"nvd:cpe","severity":"Medium","urls":["https://artifex.com/","https://bugs.ghostscript.com/show_bug.cgi?id=709328","https://github.com/biniamf/pocs/tree/main/mupdf-cff-indexload-oobread","https://vuldb.com/submit/802590","https://vuldb.com/vuln/359840","https://vuldb.com/vuln/359840/cti"],"description":"A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:N/A:N","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7233","epss":0.00238,"percentile":0.14764,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7233","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-7233","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7233","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a8856e00526f091d","name":"python3-mupdf","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-mupdf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-mupdf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.list"},{"path":"/var/lib/dpkg/info/python3-mupdf.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.postinst"},{"path":"/var/lib/dpkg/info/python3-mupdf.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3-mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-mupdf@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2024-56433","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"exploitabilityScore":1.1,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56433","epss":0.004,"percentile":0.3236,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.13199999999999998},"relatedVulnerabilities":[{"id":"CVE-2024-56433","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"exploitabilityScore":1.1,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56433","epss":0.004,"percentile":0.3236,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"}}],"artifact":{"id":"78a386fd7b15051b","name":"login.defs","version":"1:4.17.4-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.postinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:login.defs:login.defs:1\\:4.17.4-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login.defs@1%3A4.17.4-2?arch=all&distro=debian-13.5&upstream=shadow","upstreams":[{"name":"shadow"}]}},{"vulnerability":{"id":"CVE-2024-56433","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"exploitabilityScore":1.1,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56433","epss":0.004,"percentile":0.3236,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.13199999999999998},"relatedVulnerabilities":[{"id":"CVE-2024-56433","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"exploitabilityScore":1.1,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56433","epss":0.004,"percentile":0.3236,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dae81fa9c3e5095f","name":"passwd","version":"1:4.17.4-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:passwd:passwd:1\\:4.17.4-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/passwd@1%3A4.17.4-2?arch=amd64&distro=debian-13.5&upstream=shadow","upstreams":[{"name":"shadow"}]}},{"vulnerability":{"id":"CVE-2010-4756","dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[],"epss":[{"cve":"CVE-2010-4756","epss":0.02633,"percentile":0.83839,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13165},"relatedVulnerabilities":[{"id":"CVE-2010-4756","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","namespace":"nvd:cpe","severity":"Medium","urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"exploitabilityScore":8,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2010-4756","epss":0.02633,"percentile":0.83839,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1ded7e36f657ba6e","name":"libc-bin","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2010-4756","dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[],"epss":[{"cve":"CVE-2010-4756","epss":0.02633,"percentile":0.83839,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13165},"relatedVulnerabilities":[{"id":"CVE-2010-4756","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","namespace":"nvd:cpe","severity":"Medium","urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"exploitabilityScore":8,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2010-4756","epss":0.02633,"percentile":0.83839,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1e14850bd315eb8f","name":"libc6","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2023-39328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39328","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39328","epss":0.00242,"percentile":0.15354,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-39328","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12705},"relatedVulnerabilities":[{"id":"CVE-2023-39328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39328","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2023-39328","https://bugzilla.redhat.com/show_bug.cgi?id=2219236","https://github.com/uclouvain/openjpeg/issues/1476","https://github.com/uclouvain/openjpeg/pull/1470","https://github.com/uclouvain/openjpeg/pull/1471"],"description":"A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39328","epss":0.00242,"percentile":0.15354,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-39328","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-39328","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2019-9192","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[],"epss":[{"cve":"CVE-2019-9192","epss":0.02447,"percentile":0.82537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12235},"relatedVulnerabilities":[{"id":"CVE-2019-9192","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-9192","epss":0.02447,"percentile":0.82537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1ded7e36f657ba6e","name":"libc-bin","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-9192","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[],"epss":[{"cve":"CVE-2019-9192","epss":0.02447,"percentile":0.82537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12235},"relatedVulnerabilities":[{"id":"CVE-2019-9192","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-9192","epss":0.02447,"percentile":0.82537,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1e14850bd315eb8f","name":"libc6","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2020-15719","dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15719","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.","cvss":[],"epss":[{"cve":"CVE-2020-15719","epss":0.02417,"percentile":0.82303,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12085000000000001},"relatedVulnerabilities":[{"id":"CVE-2020-15719","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15719","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00033.html","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00059.html","https://access.redhat.com/errata/RHBA-2019:3674","https://bugs.openldap.org/show_bug.cgi?id=9266","https://bugzilla.redhat.com/show_bug.cgi?id=1740070","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"exploitabilityScore":1.7,"impactScore":2.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"exploitabilityScore":5,"impactScore":5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-15719","epss":0.02417,"percentile":0.82303,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2020-15719","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34614e72922d8e4b","name":"libldap2","version":"2.6.10+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.5&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2026-50219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50219","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50219","epss":0.00218,"percentile":0.12274,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-50219","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11881000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-50219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50219","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1246"],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50219","epss":0.00218,"percentile":0.12274,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-50219","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-50219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2019-1010025","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[],"epss":[{"cve":"CVE-2019-1010025","epss":0.02286,"percentile":0.81246,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11429999999999998},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","namespace":"nvd:cpe","severity":"Medium","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010025","epss":0.02286,"percentile":0.81246,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1ded7e36f657ba6e","name":"libc-bin","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010025","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[],"epss":[{"cve":"CVE-2019-1010025","epss":0.02286,"percentile":0.81246,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11429999999999998},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","namespace":"nvd:cpe","severity":"Medium","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010025","epss":0.02286,"percentile":0.81246,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1e14850bd315eb8f","name":"libc6","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-58055","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58055","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58055","epss":0.00202,"percentile":0.10257,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.11413000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-58055","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc","https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e","https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"],"description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.3,"impactScore":2.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58055","epss":0.00202,"percentile":0.10257,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"nghttp2","version":"1.64.0-1.1+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-58055","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3c5ce3f8eabd0710","name":"libnghttp2-14","version":"1.64.0-1.1+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnghttp2-14@1.64.0-1.1%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=nghttp2","upstreams":[{"name":"nghttp2"}]}},{"vulnerability":{"id":"CVE-2026-32777","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32777","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.7.5 allows an infinite loop while parsing DTD content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32777","epss":0.00216,"percentile":0.12026,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1134},"relatedVulnerabilities":[{"id":"CVE-2026-32777","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32777","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/issues/1161","https://github.com/libexpat/libexpat/pull/1159","https://github.com/libexpat/libexpat/pull/1162","https://issues.oss-fuzz.com/issues/486993411","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.7.5 allows an infinite loop while parsing DTD content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32777","epss":0.00216,"percentile":0.12026,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-32777","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2016-9116","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9116","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[],"epss":[{"cve":"CVE-2016-9116","epss":0.02236,"percentile":0.80834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9116","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11180000000000001},"relatedVulnerabilities":[{"id":"CVE-2016-9116","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9116","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/93975","https://github.com/uclouvain/openjpeg/issues/859","https://security.gentoo.org/glsa/201710-26"],"description":"NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9116","epss":0.02236,"percentile":0.80834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9116","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2016-9116","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2016-9117","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9117","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[],"epss":[{"cve":"CVE-2016-9117","epss":0.02216,"percentile":0.80666,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9117","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11080000000000001},"relatedVulnerabilities":[{"id":"CVE-2016-9117","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9117","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/93783","https://github.com/uclouvain/openjpeg/issues/860","https://security.gentoo.org/glsa/201710-26"],"description":"NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9117","epss":0.02216,"percentile":0.80666,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9117","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2016-9117","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-1757","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1757","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1757","epss":0.00194,"percentile":0.09306,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1757","cwe":"CWE-401","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":["2.12.7+dfsg+really2.9.14-2.1+deb13u3"],"state":"fixed","available":[{"version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.10864000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-1757","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1757","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-1757","https://bugzilla.redhat.com/show_bug.cgi?id=2435940","https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009"],"description":"A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1757","epss":0.00194,"percentile":0.09306,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-1757","cwe":"CWE-401","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-1757","versionConstraint":"< 2.12.7+dfsg+really2.9.14-2.1+deb13u3 (deb)"},"fix":{"suggestedVersion":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"}}],"artifact":{"id":"07fee9125970d2ca","name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2012-0039","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-0039","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.","cvss":[],"epss":[{"cve":"CVE-2012-0039","epss":0.02162,"percentile":0.8019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-0039","cwe":"CWE-310","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10810000000000002},"relatedVulnerabilities":[{"id":"CVE-2012-0039","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-0039","namespace":"nvd:cpe","severity":"Medium","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=655044","http://mail.gnome.org/archives/gtk-devel-list/2003-May/msg00111.html","http://openwall.com/lists/oss-security/2012/01/10/12","https://bugzilla.redhat.com/show_bug.cgi?id=772720"],"description":"GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-0039","epss":0.02162,"percentile":0.8019,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2012-0039","cwe":"CWE-310","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glib2.0","version":"2.84.4-3~deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2012-0039","versionConstraint":"none (unknown)"}}],"artifact":{"id":"40a29caaab142509","name":"libglib2.0-0t64","version":"2.84.4-3~deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libglib2.0-0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0t64@2.84.4-3~deb13u3?arch=amd64&distro=debian-13.5&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2016-10505","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-10505","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.","cvss":[],"epss":[{"cve":"CVE-2016-10505","epss":0.02149,"percentile":0.8008,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-10505","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10744999999999999},"relatedVulnerabilities":[{"id":"CVE-2016-10505","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-10505","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/uclouvain/openjpeg/issues/776","https://github.com/uclouvain/openjpeg/issues/784","https://github.com/uclouvain/openjpeg/issues/785","https://github.com/uclouvain/openjpeg/issues/792","https://security.gentoo.org/glsa/201710-26"],"description":"NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-10505","epss":0.02149,"percentile":0.8008,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-10505","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2016-10505","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-27171","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27171","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27171","epss":0.00204,"percentile":0.1043,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.10710000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-27171","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","namespace":"nvd:cpe","severity":"Medium","urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27171","epss":0.00204,"percentile":0.1043,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a433147e5a18c5d9","name":"zlib1g","version":"1:1.3.dfsg+really1.3.1-1+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.5&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]}},{"vulnerability":{"id":"CVE-2026-34933","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34933","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10361,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2026-34933","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34933","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/625ca0fac19229f6dfa3a6c6b698ae657187e50c","https://github.com/avahi/avahi/pull/891","https://github.com/avahi/avahi/security/advisories/GHSA-w65r-6gxh-vhvc","http://www.openwall.com/lists/oss-security/2026/04/11/9"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10361,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-34933","versionConstraint":"none (unknown)"}}],"artifact":{"id":"337bbef46c41fed2","name":"libavahi-client3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-34933","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34933","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10361,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2026-34933","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34933","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/625ca0fac19229f6dfa3a6c6b698ae657187e50c","https://github.com/avahi/avahi/pull/891","https://github.com/avahi/avahi/security/advisories/GHSA-w65r-6gxh-vhvc","http://www.openwall.com/lists/oss-security/2026/04/11/9"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10361,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-34933","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1eab38231de446ba","name":"libavahi-common-data","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-34933","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34933","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10361,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2026-34933","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34933","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/625ca0fac19229f6dfa3a6c6b698ae657187e50c","https://github.com/avahi/avahi/pull/891","https://github.com/avahi/avahi/security/advisories/GHSA-w65r-6gxh-vhvc","http://www.openwall.com/lists/oss-security/2026/04/11/9"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10361,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-34933","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eaca5e0133dcdd02","name":"libavahi-common3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2016-9115","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9115","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[],"epss":[{"cve":"CVE-2016-9115","epss":0.02128,"percentile":0.79885,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9115","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10640000000000001},"relatedVulnerabilities":[{"id":"CVE-2016-9115","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9115","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/93977","https://github.com/uclouvain/openjpeg/issues/858","https://security.gentoo.org/glsa/201710-26"],"description":"Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9115","epss":0.02128,"percentile":0.79885,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9115","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2016-9115","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2015-9019","dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-9019","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.","cvss":[],"epss":[{"cve":"CVE-2015-9019","epss":0.02122,"percentile":0.79827,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2015-9019","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10610000000000001},"relatedVulnerabilities":[{"id":"CVE-2015-9019","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-9019","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.gnome.org/show_bug.cgi?id=758400","https://bugzilla.suse.com/show_bug.cgi?id=934119"],"description":"In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-9019","epss":0.02122,"percentile":0.79827,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2015-9019","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libxslt","version":"1.1.35-1.2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2015-9019","versionConstraint":"none (unknown)"}}],"artifact":{"id":"135a4dccfe3c34a3","name":"libxslt1.1","version":"1.1.35-1.2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libxslt1.1:libxslt1.1:1.1.35-1.2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxslt1.1@1.1.35-1.2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=libxslt","upstreams":[{"name":"libxslt"}]}},{"vulnerability":{"id":"CVE-2026-54369","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54369","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54369","epss":0.00142,"percentile":0.03949,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-54369","cwe":"CWE-59","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.10365999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-54369","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","namespace":"nvd:cpe","severity":"High","urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54369","epss":0.00142,"percentile":0.03949,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-54369","cwe":"CWE-59","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"acl","version":"2.3.2-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6605da99722fd0ea","name":"libacl1","version":"2.3.2-2+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-2\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libacl1@2.3.2-2%2Bb1?arch=amd64&distro=debian-13.5&upstream=acl%402.3.2-2","upstreams":[{"name":"acl","version":"2.3.2-2"}]}},{"vulnerability":{"id":"CVE-2018-5709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.79267,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10335000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-5709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.79267,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1233a8cb20b5da22","name":"libgssapi-krb5-2","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2018-5709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.79267,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10335000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-5709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.79267,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34c33399cc1862e4","name":"libk5crypto3","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libk5crypto3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2018-5709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.79267,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10335000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-5709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.79267,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34b3a0e5c1bc108a","name":"libkrb5-3","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5-3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2018-5709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.79267,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10335000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-5709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.79267,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"54c1c867e4d0ece0","name":"libkrb5support0","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5support0@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2016-9580","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9580","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.","cvss":[],"epss":[{"cve":"CVE-2016-9580","epss":0.0202,"percentile":0.78766,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9580","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9580","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9580","cwe":"CWE-190","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.101},"relatedVulnerabilities":[{"id":"CVE-2016-9580","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9580","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/94822","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9580","https://github.com/szukw000/openjpeg/commit/cadff5fb6e73398de26a92e96d3d7cac893af255","https://github.com/uclouvain/openjpeg/issues/871","https://security.gentoo.org/glsa/201710-26"],"description":"An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9580","epss":0.0202,"percentile":0.78766,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9580","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9580","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9580","cwe":"CWE-190","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2016-9580","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2017-2818","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-2818","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacker controlled PDF file can be used to trigger this vulnerability.","cvss":[],"epss":[{"cve":"CVE-2017-2818","epss":0.01977,"percentile":0.78266,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-2818","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09885000000000001},"relatedVulnerabilities":[{"id":"CVE-2017-2818","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-2818","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/99497","https://talosintelligence.com/vulnerability_reports/TALOS-2017-0319"],"description":"An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacker controlled PDF file can be used to trigger this vulnerability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"talos-cna@cisco.com","type":"Secondary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-2818","epss":0.01977,"percentile":0.78266,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-2818","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"poppler","version":"25.03.0-5+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-2818","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f9378ee2c5fb55fb","name":"libpoppler147","version":"25.03.0-5+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpoppler147:libpoppler147:25.03.0-5\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpoppler147@25.03.0-5%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=poppler","upstreams":[{"name":"poppler"}]}},{"vulnerability":{"id":"CVE-2025-66382","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66382","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66382","epss":0.00188,"percentile":0.08529,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09870000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-66382","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66382","epss":0.00188,"percentile":0.08529,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2016-9581","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9581","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.","cvss":[],"epss":[{"cve":"CVE-2016-9581","epss":0.01969,"percentile":0.78173,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9581","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9581","cwe":"CWE-835","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9581","cwe":"CWE-119","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09845},"relatedVulnerabilities":[{"id":"CVE-2016-9581","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9581","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/94822","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9581","https://github.com/szukw000/openjpeg/commit/cadff5fb6e73398de26a92e96d3d7cac893af255","https://github.com/uclouvain/openjpeg/issues/872","https://security.gentoo.org/glsa/201710-26"],"description":"An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9581","epss":0.01969,"percentile":0.78173,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2016-9581","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9581","cwe":"CWE-835","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9581","cwe":"CWE-119","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2016-9581","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2a798787eca67b6","name":"libopenjp2-7","version":"2.5.3-2.1~deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.5&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2018-10126","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10126","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.","cvss":[],"epss":[{"cve":"CVE-2018-10126","epss":0.0187,"percentile":0.76994,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10126","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0935},"relatedVulnerabilities":[{"id":"CVE-2018-10126","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10126","namespace":"nvd:cpe","severity":"Medium","urls":["http://bugzilla.maptools.org/show_bug.cgi?id=2786","https://gitlab.com/libtiff/libtiff/-/issues/128","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10126","epss":0.0187,"percentile":0.76994,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-10126","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tiff","version":"4.7.0-3+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-10126","versionConstraint":"none (unknown)"}}],"artifact":{"id":"632b90e0e50cde2d","name":"libtiff6","version":"4.7.0-3+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2022-1210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-1210","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used.","cvss":[],"epss":[{"cve":"CVE-2022-1210","epss":0.01851,"percentile":0.76748,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-1210","cwe":"CWE-400","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2022-1210","cwe":"CWE-404","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09255},"relatedVulnerabilities":[{"id":"CVE-2022-1210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1210","namespace":"nvd:cpe","severity":"Medium","urls":["https://gitlab.com/libtiff/libtiff/-/issues/402","https://gitlab.com/libtiff/libtiff/uploads/c3da94e53cf1e1e8e6d4d3780dc8c42f/example.tiff","https://security.gentoo.org/glsa/202210-10","https://security.netapp.com/advisory/ntap-20220513-0005/","https://vuldb.com/?id.196363"],"description":"A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-1210","epss":0.01851,"percentile":0.76748,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-1210","cwe":"CWE-400","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2022-1210","cwe":"CWE-404","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tiff","version":"4.7.0-3+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-1210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"632b90e0e50cde2d","name":"libtiff6","version":"4.7.0-3+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-0992","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0992","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0992","epss":0.00308,"percentile":0.22793,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0992","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":["2.12.7+dfsg+really2.9.14-2.1+deb13u3"],"state":"fixed","available":[{"version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.09085999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-0992","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0992","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-0992","https://bugzilla.redhat.com/show_bug.cgi?id=2429975","https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019"],"description":"A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0992","epss":0.00308,"percentile":0.22793,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0992","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-0992","versionConstraint":"< 2.12.7+dfsg+really2.9.14-2.1+deb13u3 (deb)"},"fix":{"suggestedVersion":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"}}],"artifact":{"id":"07fee9125970d2ca","name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2018-6829","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6829","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.","cvss":[],"epss":[{"cve":"CVE-2018-6829","epss":0.01811,"percentile":0.76203,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09055},"relatedVulnerabilities":[{"id":"CVE-2018-6829","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6829","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/weikengchen/attack-on-libgcrypt-elgamal","https://github.com/weikengchen/attack-on-libgcrypt-elgamal/wiki","https://lists.gnupg.org/pipermail/gcrypt-devel/2018-February/004394.html","https://www.oracle.com/security-alerts/cpujan2020.html"],"description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-6829","epss":0.01811,"percentile":0.76203,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libgcrypt20","version":"1.11.0-7+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-6829","versionConstraint":"none (unknown)"}}],"artifact":{"id":"812c0cdf7cc881e3","name":"libgcrypt20","version":"1.11.0-7+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.11.0-7\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgcrypt20@1.11.0-7%2Bdeb13u1?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-32778","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32778","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32778","epss":0.00166,"percentile":0.06129,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-32778","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08715},"relatedVulnerabilities":[{"id":"CVE-2026-32778","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32778","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1159","https://github.com/libexpat/libexpat/pull/1163","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32778","epss":0.00166,"percentile":0.06129,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-32778","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-32778","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-32776","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32776","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32776","epss":0.00164,"percentile":0.0598,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-32776","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0861},"relatedVulnerabilities":[{"id":"CVE-2026-32776","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32776","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1158","https://github.com/libexpat/libexpat/pull/1159","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32776","epss":0.00164,"percentile":0.0598,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-32776","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-32776","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2025-10911","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10911","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10911","epss":0.00161,"percentile":0.05685,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-10911","cwe":"CWE-825","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.084525},"relatedVulnerabilities":[{"id":"CVE-2025-10911","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10911","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:11015","https://access.redhat.com/errata/RHSA-2026:26355","https://access.redhat.com/errata/RHSA-2026:28243","https://access.redhat.com/errata/RHSA-2026:28584","https://access.redhat.com/errata/RHSA-2026:29807","https://access.redhat.com/errata/RHSA-2026:29809","https://access.redhat.com/errata/RHSA-2026:29811","https://access.redhat.com/errata/RHSA-2026:29814","https://access.redhat.com/errata/RHSA-2026:29975","https://access.redhat.com/errata/RHSA-2026:29976","https://access.redhat.com/errata/RHSA-2026:30847","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/security/cve/CVE-2025-10911","https://bugzilla.redhat.com/show_bug.cgi?id=2397838","https://gitlab.gnome.org/GNOME/libxslt/-/issues/144","https://gitlab.gnome.org/GNOME/libxslt/-/merge_requests/77"],"description":"A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10911","epss":0.00161,"percentile":0.05685,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-10911","cwe":"CWE-825","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libxslt","version":"1.1.35-1.2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-10911","versionConstraint":"none (unknown)"}}],"artifact":{"id":"135a4dccfe3c34a3","name":"libxslt1.1","version":"1.1.35-1.2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libxslt1.1:libxslt1.1:1.1.35-1.2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxslt1.1@1.1.35-1.2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=libxslt","upstreams":[{"name":"libxslt"}]}},{"vulnerability":{"id":"CVE-2026-50593","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50593","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50593","epss":0.00112,"percentile":0.01645,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-50593","cwe":"CWE-191","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["1.3.14-2+deb13u1"],"state":"fixed","available":[{"version":"1.3.14-2+deb13u1","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.08287999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-50593","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50593","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/silnrsi/graphite/commit/ad78c6b7319909e1540c1b134e115ced03417866","https://github.com/silnrsi/graphite/compare/1.3.14...1.3.15"],"description":"Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50593","epss":0.00112,"percentile":0.01645,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-50593","cwe":"CWE-191","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"graphite2","version":"1.3.14-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-50593","versionConstraint":"< 1.3.14-2+deb13u1 (deb)"},"fix":{"suggestedVersion":"1.3.14-2+deb13u1"}}],"artifact":{"id":"5600d4e859112cc6","name":"libgraphite2-3","version":"1.3.14-2+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgraphite2-3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libgraphite2-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libgraphite2-3:libgraphite2-3:1.3.14-2\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libgraphite2-3:libgraphite2_3:1.3.14-2\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libgraphite2_3:libgraphite2-3:1.3.14-2\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libgraphite2_3:libgraphite2_3:1.3.14-2\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libgraphite2:libgraphite2-3:1.3.14-2\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libgraphite2:libgraphite2_3:1.3.14-2\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgraphite2-3@1.3.14-2%2Bb1?arch=amd64&distro=debian-13.5&upstream=graphite2%401.3.14-2","upstreams":[{"name":"graphite2","version":"1.3.14-2"}]}},{"vulnerability":{"id":"CVE-2025-59529","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59529","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00155,"percentile":0.05089,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.081375},"relatedVulnerabilities":[{"id":"CVE-2025-59529","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00155,"percentile":0.05089,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"}}],"artifact":{"id":"337bbef46c41fed2","name":"libavahi-client3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-59529","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59529","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00155,"percentile":0.05089,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.081375},"relatedVulnerabilities":[{"id":"CVE-2025-59529","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00155,"percentile":0.05089,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1eab38231de446ba","name":"libavahi-common-data","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-59529","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59529","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00155,"percentile":0.05089,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.081375},"relatedVulnerabilities":[{"id":"CVE-2025-59529","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00155,"percentile":0.05089,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eaca5e0133dcdd02","name":"libavahi-common3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-40505","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40505","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40505","epss":0.00166,"percentile":0.06189,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-40505","cwe":"CWE-150","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08134000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-40505","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40505","namespace":"nvd:cpe","severity":"Medium","urls":["https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=0f17d789fe8c29b41e47663be82514aaca3a4dfb","https://github.com/ArtifexSoftware/mupdf/commit/0f17d789fe8c29b41e47663be82514aaca3a4dfb","https://github.com/ArtifexSoftware/mupdf/releases/tag/1.27.0","https://www.vulncheck.com/advisories/mupdf-mutool-ansi-injection-via-metadata"],"description":"MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40505","epss":0.00166,"percentile":0.06189,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-40505","cwe":"CWE-150","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-40505","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6de3a4b2ce25dd7","name":"libmupdf25.1","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.list"},{"path":"/var/lib/dpkg/info/libmupdf25.1.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.shlibs"},{"path":"/var/lib/dpkg/info/libmupdf25.1.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.symbols"},{"path":"/var/lib/dpkg/info/libmupdf25.1.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmupdf25.1:libmupdf25.1:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmupdf25.1@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2026-40505","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40505","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40505","epss":0.00166,"percentile":0.06189,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-40505","cwe":"CWE-150","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08134000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-40505","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40505","namespace":"nvd:cpe","severity":"Medium","urls":["https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=0f17d789fe8c29b41e47663be82514aaca3a4dfb","https://github.com/ArtifexSoftware/mupdf/commit/0f17d789fe8c29b41e47663be82514aaca3a4dfb","https://github.com/ArtifexSoftware/mupdf/releases/tag/1.27.0","https://www.vulncheck.com/advisories/mupdf-mutool-ansi-injection-via-metadata"],"description":"MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40505","epss":0.00166,"percentile":0.06189,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-40505","cwe":"CWE-150","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-40505","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a8856e00526f091d","name":"python3-mupdf","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-mupdf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-mupdf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.list"},{"path":"/var/lib/dpkg/info/python3-mupdf.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.postinst"},{"path":"/var/lib/dpkg/info/python3-mupdf.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3-mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-mupdf@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2025-6141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00165,"percentile":0.06115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08084999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-6141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","namespace":"nvd:cpe","severity":"Medium","urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00165,"percentile":0.06115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4a4ab661d3b349cf","name":"libncursesw6","version":"6.5+20250216-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libncursesw6@6.5%2B20250216-2?arch=amd64&distro=debian-13.5&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-6141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00165,"percentile":0.06115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08084999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-6141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","namespace":"nvd:cpe","severity":"Medium","urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00165,"percentile":0.06115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eb0b686927e474b5","name":"libtinfo6","version":"6.5+20250216-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64&distro=debian-13.5&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-6141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00165,"percentile":0.06115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08084999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-6141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","namespace":"nvd:cpe","severity":"Medium","urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00165,"percentile":0.06115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"58f1158b1e8f496a","name":"ncurses-base","version":"6.5+20250216-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all&distro=debian-13.5&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-6141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00165,"percentile":0.06115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08084999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-6141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","namespace":"nvd:cpe","severity":"Medium","urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00165,"percentile":0.06115,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c53b0f13a8132bdb","name":"ncurses-bin","version":"6.5+20250216-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64&distro=debian-13.5&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-11731","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11731","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11731","epss":0.00264,"percentile":0.17989,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-11731","cwe":"CWE-843","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08052},"relatedVulnerabilities":[{"id":"CVE-2025-11731","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11731","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/errata/RHSA-2026:11015","https://access.redhat.com/security/cve/CVE-2025-11731","https://bugzilla.redhat.com/show_bug.cgi?id=2403688","https://gitlab.gnome.org/GNOME/libxslt/-/issues/151","https://gitlab.gnome.org/GNOME/libxslt/-/merge_requests/78"],"description":"A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11731","epss":0.00264,"percentile":0.17989,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-11731","cwe":"CWE-843","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libxslt","version":"1.1.35-1.2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-11731","versionConstraint":"none (unknown)"}}],"artifact":{"id":"135a4dccfe3c34a3","name":"libxslt1.1","version":"1.1.35-1.2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libxslt1.1:libxslt1.1:1.1.35-1.2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxslt1.1@1.1.35-1.2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=libxslt","upstreams":[{"name":"libxslt"}]}},{"vulnerability":{"id":"CVE-2026-54371","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54371","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54371","epss":0.00136,"percentile":0.03407,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-54371","cwe":"CWE-59","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07684},"relatedVulnerabilities":[{"id":"CVE-2026-54371","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54371","namespace":"nvd:cpe","severity":"Medium","urls":["https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f","https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b","https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr","https://access.redhat.com/errata/RHSA-2026:34889","https://access.redhat.com/security/cve/CVE-2026-54371","https://bugzilla.redhat.com/show_bug.cgi?id=2490283","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"],"description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54371","epss":0.00136,"percentile":0.03407,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-54371","cwe":"CWE-59","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"attr","version":"1:2.5.2-3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-54371","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7ab9ac952e1cc93b","name":"libattr1","version":"1:2.5.2-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libattr1:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libattr1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libattr1:libattr1:1\\:2.5.2-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libattr1@1%3A2.5.2-3?arch=amd64&distro=debian-13.5&upstream=attr","upstreams":[{"name":"attr"}]}},{"vulnerability":{"id":"CVE-2026-13757","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13757","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13757","epss":0.00137,"percentile":0.03521,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07672},"relatedVulnerabilities":[{"id":"CVE-2026-13757","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13757","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:37469","https://access.redhat.com/errata/RHSA-2026:38342","https://access.redhat.com/security/cve/CVE-2026-13757","https://bugzilla.redhat.com/show_bug.cgi?id=2494556","https://github.com/advisories/GHSA-p2wm-69qx-x25w"],"description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13757","epss":0.00137,"percentile":0.03521,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"p11-kit","version":"0.25.5-3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-13757","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0e782b6df48dd2b1","name":"libp11-kit0","version":"0.25.5-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libp11-kit0@0.25.5-3?arch=amd64&distro=debian-13.5&upstream=p11-kit","upstreams":[{"name":"p11-kit"}]}},{"vulnerability":{"id":"CVE-2018-18064","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-18064","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).","cvss":[],"epss":[{"cve":"CVE-2018-18064","epss":0.0148,"percentile":0.71028,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-18064","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07400000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-18064","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-18064","namespace":"nvd:cpe","severity":"Medium","urls":["https://gitlab.freedesktop.org/cairo/cairo/issues/341","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-18064","epss":0.0148,"percentile":0.71028,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2018-18064","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"cairo","version":"1.18.4-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2018-18064","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2efbf400f5d2550c","name":"libcairo2","version":"1.18.4-1+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcairo2:libcairo2:1.18.4-1\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo2@1.18.4-1%2Bb1?arch=amd64&distro=debian-13.5&upstream=cairo%401.18.4-1","upstreams":[{"name":"cairo","version":"1.18.4-1"}]}},{"vulnerability":{"id":"CVE-2025-68276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68276","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling the RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.0014,"percentile":0.03727,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0735},"relatedVulnerabilities":[{"id":"CVE-2025-68276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/ede7048475c5d47d53890e3bc1350dda8e0b3688","https://github.com/avahi/avahi/pull/806","https://github.com/avahi/avahi/security/advisories/GHSA-mhf3-865v-g5rc"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling\nthe RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.0014,"percentile":0.03727,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"337bbef46c41fed2","name":"libavahi-client3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68276","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling the RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.0014,"percentile":0.03727,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0735},"relatedVulnerabilities":[{"id":"CVE-2025-68276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/ede7048475c5d47d53890e3bc1350dda8e0b3688","https://github.com/avahi/avahi/pull/806","https://github.com/avahi/avahi/security/advisories/GHSA-mhf3-865v-g5rc"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling\nthe RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.0014,"percentile":0.03727,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1eab38231de446ba","name":"libavahi-common-data","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68276","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling the RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.0014,"percentile":0.03727,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0735},"relatedVulnerabilities":[{"id":"CVE-2025-68276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/ede7048475c5d47d53890e3bc1350dda8e0b3688","https://github.com/avahi/avahi/pull/806","https://github.com/avahi/avahi/security/advisories/GHSA-mhf3-865v-g5rc"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling\nthe RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.0014,"percentile":0.03727,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eaca5e0133dcdd02","name":"libavahi-common3","version":"0.8-16","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.5&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-54370","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54370","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54370","epss":0.00091,"percentile":0.00633,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.066885},"relatedVulnerabilities":[{"id":"CVE-2026-54370","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","namespace":"nvd:cpe","severity":"High","urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54370","epss":0.00091,"percentile":0.00633,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"acl","version":"2.3.2-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6605da99722fd0ea","name":"libacl1","version":"2.3.2-2+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-2\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libacl1@2.3.2-2%2Bb1?arch=amd64&distro=debian-13.5&upstream=acl%402.3.2-2","upstreams":[{"name":"acl","version":"2.3.2-2"}]}},{"vulnerability":{"id":"CVE-2026-56131","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56131","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56131","epss":0.00135,"percentile":0.03337,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56131","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066825},"relatedVulnerabilities":[{"id":"CVE-2026-56131","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56131","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1267"],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56131","epss":0.00135,"percentile":0.03337,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56131","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56131","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56410","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56410","epss":0.0011,"percentile":0.01507,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56410","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06545000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-56410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56410","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1252"],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56410","epss":0.0011,"percentile":0.01507,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56410","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56410","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56411","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56411","epss":0.0011,"percentile":0.01507,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56411","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06545000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-56411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56411","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1263"],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56411","epss":0.0011,"percentile":0.01507,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56411","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56411","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56132","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56132","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56132","epss":0.00107,"percentile":0.01361,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56132","cwe":"CWE-821","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063665},"relatedVulnerabilities":[{"id":"CVE-2026-56132","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56132","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1272"],"description":"In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56132","epss":0.00107,"percentile":0.01361,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56132","cwe":"CWE-821","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56132","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2025-50422","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-50422","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"Cairo through 1.18.4, as used in Poppler through 25.08.0, has an \"unscaled->face == NULL\" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-50422","epss":0.00213,"percentile":0.1165,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-50422","cwe":"CWE-617","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.062835},"relatedVulnerabilities":[{"id":"CVE-2025-50422","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-50422","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/Landw-hub/CVE-2025-50422","https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/621","https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591","https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591#note_3045081"],"description":"Cairo through 1.18.4, as used in Poppler through 25.08.0, has an \"unscaled->face == NULL\" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-50422","epss":0.00213,"percentile":0.1165,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-50422","cwe":"CWE-617","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"cairo","version":"1.18.4-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-50422","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2efbf400f5d2550c","name":"libcairo2","version":"1.18.4-1+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcairo2:libcairo2:1.18.4-1\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo2@1.18.4-1%2Bb1?arch=amd64&distro=debian-13.5&upstream=cairo%401.18.4-1","upstreams":[{"name":"cairo","version":"1.18.4-1"}]}},{"vulnerability":{"id":"CVE-2026-42250","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42250","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).  This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67","cvss":[{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42250","epss":0.00126,"percentile":0.02689,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06174},"relatedVulnerabilities":[{"id":"CVE-2026-42250","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","namespace":"nvd:cpe","severity":"Medium","urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67","cvss":[{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42250","epss":0.00126,"percentile":0.02689,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"bzip2","version":"1.0.8-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"}}],"artifact":{"id":"57777f201f8a0e58","name":"libbz2-1.0","version":"1.0.8-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2-1.0:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbz2-1.0@1.0.8-6?arch=amd64&distro=debian-13.5&upstream=bzip2","upstreams":[{"name":"bzip2"}]}},{"vulnerability":{"id":"CVE-2026-56403","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56403","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in storeAtts.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56403","epss":0.00102,"percentile":0.01149,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56403","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06069000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-56403","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56403","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1232"],"description":"libexpat before 2.8.2 has an integer overflow in storeAtts.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56403","epss":0.00102,"percentile":0.01149,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56403","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56403","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56405","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56405","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in getAttributeId.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56405","epss":0.00102,"percentile":0.01149,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56405","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06069000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-56405","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56405","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1251"],"description":"libexpat before 2.8.2 has an integer overflow in getAttributeId.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56405","epss":0.00102,"percentile":0.01149,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56405","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56405","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56408","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in copyString.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56408","epss":0.00102,"percentile":0.01149,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56408","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06069000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-56408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56408","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817"],"description":"libexpat before 2.8.2 has an integer overflow in copyString.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56408","epss":0.00102,"percentile":0.01149,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56408","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56404","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56404","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in addBinding.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56404","epss":0.00102,"percentile":0.01148,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56404","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06069000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-56404","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56404","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1249"],"description":"libexpat before 2.8.2 has an integer overflow in addBinding.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56404","epss":0.00102,"percentile":0.01148,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56404","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56404","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56406","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56406","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56406","epss":0.00102,"percentile":0.01114,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56406","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06069000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-56406","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56406","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1255"],"description":"libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56406","epss":0.00102,"percentile":0.01114,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56406","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56406","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56407","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56407","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56407","epss":0.00102,"percentile":0.01114,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56407","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06069000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-56407","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56407","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1262"],"description":"libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56407","epss":0.00102,"percentile":0.01114,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56407","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56407","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2011-3374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3374","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.","cvss":[],"epss":[{"cve":"CVE-2011-3374","epss":0.01191,"percentile":0.64488,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05955000000000001},"relatedVulnerabilities":[{"id":"CVE-2011-3374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3374","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/cve-2011-3374","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642480","https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.html","https://seclists.org/fulldisclosure/2011/Sep/221","https://security-tracker.debian.org/tracker/CVE-2011-3374","https://snyk.io/vuln/SNYK-LINUX-APT-116518","https://ubuntu.com/security/CVE-2011-3374"],"description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-3374","epss":0.01191,"percentile":0.64488,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"apt","version":"3.0.3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2011-3374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4fe61e664cb0ce20","name":"apt","version":"3.0.3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/apt.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/apt.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/apt.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/apt.list"},{"path":"/var/lib/dpkg/info/apt.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/apt.postinst"},{"path":"/var/lib/dpkg/info/apt.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/apt.postrm"},{"path":"/var/lib/dpkg/info/apt.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/apt.preinst"},{"path":"/var/lib/dpkg/info/apt.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/apt.prerm"},{"path":"/var/lib/dpkg/info/apt.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/apt.shlibs"},{"path":"/var/lib/dpkg/info/apt.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/apt.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:apt:apt:3.0.3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/apt@3.0.3?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2011-3374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3374","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.","cvss":[],"epss":[{"cve":"CVE-2011-3374","epss":0.01191,"percentile":0.64488,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05955000000000001},"relatedVulnerabilities":[{"id":"CVE-2011-3374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3374","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/cve-2011-3374","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642480","https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.html","https://seclists.org/fulldisclosure/2011/Sep/221","https://security-tracker.debian.org/tracker/CVE-2011-3374","https://snyk.io/vuln/SNYK-LINUX-APT-116518","https://ubuntu.com/security/CVE-2011-3374"],"description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-3374","epss":0.01191,"percentile":0.64488,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"apt","version":"3.0.3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2011-3374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"77d7527bbbbe1805","name":"apt-transport-https","version":"3.0.3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/apt-transport-https.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/apt-transport-https.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt-transport-https.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/apt-transport-https.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:apt-transport-https:apt-transport-https:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:apt-transport-https:apt_transport_https:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:apt_transport_https:apt-transport-https:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:apt_transport_https:apt_transport_https:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:apt-transport:apt-transport-https:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:apt-transport:apt_transport_https:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:apt_transport:apt-transport-https:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:apt_transport:apt_transport_https:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:apt:apt-transport-https:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:apt:apt_transport_https:3.0.3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/apt-transport-https@3.0.3?arch=all&distro=debian-13.5&upstream=apt","upstreams":[{"name":"apt"}]}},{"vulnerability":{"id":"CVE-2011-3374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3374","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.","cvss":[],"epss":[{"cve":"CVE-2011-3374","epss":0.01191,"percentile":0.64488,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05955000000000001},"relatedVulnerabilities":[{"id":"CVE-2011-3374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3374","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/cve-2011-3374","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642480","https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.html","https://seclists.org/fulldisclosure/2011/Sep/221","https://security-tracker.debian.org/tracker/CVE-2011-3374","https://snyk.io/vuln/SNYK-LINUX-APT-116518","https://ubuntu.com/security/CVE-2011-3374"],"description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-3374","epss":0.01191,"percentile":0.64488,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"apt","version":"3.0.3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2011-3374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e208a295bae04d84","name":"libapt-pkg7.0","version":"3.0.3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libapt-pkg7.0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libapt-pkg7.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libapt-pkg7.0:libapt-pkg7.0:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:libapt-pkg7.0:libapt_pkg7.0:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg7.0:libapt-pkg7.0:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg7.0:libapt_pkg7.0:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt-pkg7.0:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt_pkg7.0:3.0.3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libapt-pkg7.0@3.0.3?arch=amd64&distro=debian-13.5&upstream=apt","upstreams":[{"name":"apt"}]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00128,"percentile":0.02782,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05823999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00128,"percentile":0.02782,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00128,"percentile":0.02782,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05823999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00128,"percentile":0.02782,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00128,"percentile":0.02782,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05823999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00128,"percentile":0.02782,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00128,"percentile":0.02782,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05823999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00128,"percentile":0.02782,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00128,"percentile":0.02782,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05823999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00128,"percentile":0.02782,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.057679999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"943eceb0b62d5077","name":"bsdutils","version":"1:2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.057679999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"789c9c1c32d67963","name":"libblkid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.057679999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1c14db01751ab35","name":"liblastlog2-2","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.057679999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f2906fa44fcde82e","name":"libmount1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.057679999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6bc0f11ba93c58e0","name":"libsmartcols1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.057679999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b9befafdeaa440fd","name":"libuuid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.057679999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dc55662712ce7274","name":"login","version":"1:4.16.0-2+really2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.057679999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0adc54d0e11f3b69","name":"mount","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.057679999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00112,"percentile":0.01622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3accc11c0ad101fe","name":"util-linux","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"943eceb0b62d5077","name":"bsdutils","version":"1:2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"789c9c1c32d67963","name":"libblkid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1c14db01751ab35","name":"liblastlog2-2","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f2906fa44fcde82e","name":"libmount1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6bc0f11ba93c58e0","name":"libsmartcols1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b9befafdeaa440fd","name":"libuuid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dc55662712ce7274","name":"login","version":"1:4.16.0-2+really2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0adc54d0e11f3b69","name":"mount","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.02005,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3accc11c0ad101fe","name":"util-linux","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-56412","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56412","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56412","epss":0.00105,"percentile":0.01254,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56412","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.057225000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-56412","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56412","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1278"],"description":"libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56412","epss":0.00105,"percentile":0.01254,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56412","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56412","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2024-26461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.62731,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056400000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-26461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.62731,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1233a8cb20b5da22","name":"libgssapi-krb5-2","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.62731,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056400000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-26461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.62731,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34c33399cc1862e4","name":"libk5crypto3","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libk5crypto3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.62731,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056400000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-26461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.62731,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34b3a0e5c1bc108a","name":"libkrb5-3","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5-3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.62731,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056400000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-26461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.62731,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"54c1c867e4d0ece0","name":"libkrb5support0","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5support0@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2026-56409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56409","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":1.1,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56409","epss":0.00098,"percentile":0.00951,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56409","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05635},"relatedVulnerabilities":[{"id":"CVE-2026-56409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56409","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1259"],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":1.1,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56409","epss":0.00098,"percentile":0.00951,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-56409","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-56409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2017-9083","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-9083","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.","cvss":[],"epss":[{"cve":"CVE-2017-9083","epss":0.01118,"percentile":0.62467,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-9083","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.055900000000000005},"relatedVulnerabilities":[{"id":"CVE-2017-9083","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9083","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.freedesktop.org/show_bug.cgi?id=101084","https://security.gentoo.org/glsa/201801-17"],"description":"poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-9083","epss":0.01118,"percentile":0.62467,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-9083","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"poppler","version":"25.03.0-5+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-9083","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f9378ee2c5fb55fb","name":"libpoppler147","version":"25.03.0-5+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpoppler147:libpoppler147:25.03.0-5\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpoppler147@25.03.0-5%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=poppler","upstreams":[{"name":"poppler"}]}},{"vulnerability":{"id":"CVE-2024-2236","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-2236","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.","cvss":[],"epss":[{"cve":"CVE-2024-2236","epss":0.01114,"percentile":0.62366,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","source":"secalert@redhat.com","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.055700000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-2236","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2236","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2024:9404","https://access.redhat.com/errata/RHSA-2025:3530","https://access.redhat.com/errata/RHSA-2025:3534","https://access.redhat.com/security/cve/CVE-2024-2236","https://bugzilla.redhat.com/show_bug.cgi?id=2245218","https://bugzilla.redhat.com/show_bug.cgi?id=2268268"],"description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-2236","epss":0.01114,"percentile":0.62366,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","source":"secalert@redhat.com","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libgcrypt20","version":"1.11.0-7+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-2236","versionConstraint":"none (unknown)"}}],"artifact":{"id":"812c0cdf7cc881e3","name":"libgcrypt20","version":"1.11.0-7+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.11.0-7\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgcrypt20@1.11.0-7%2Bdeb13u1?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-40228","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06944,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05449499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-40228","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06944,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7b65794238bbb047","name":"libsystemd0","version":"257.13-1~deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64&distro=debian-13.5&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-40228","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06944,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05449499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-40228","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06944,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7eaf5069148b010f","name":"libudev1","version":"257.13-1~deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libudev1:libudev1:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64&distro=debian-13.5&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-41991","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41991","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.  This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41991","epss":0.00105,"percentile":0.01294,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-41991","cwe":"CWE-377","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05092499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-41991","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41991","namespace":"nvd:cpe","severity":"Medium","urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269","https://www.gnu.org/software/gzip/"],"description":"GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.\n\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41991","epss":0.00105,"percentile":0.01294,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-41991","cwe":"CWE-377","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gzip","version":"1.13-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-41991","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c921f12dfe29d361","name":"gzip","version":"1.13-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gzip.list"},{"path":"/var/lib/dpkg/info/gzip.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gzip.postinst"},{"path":"/var/lib/dpkg/info/gzip.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gzip.preinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gzip:gzip:1.13-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gzip@1.13-1?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-8732","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8732","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that \"[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all.\"","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8732","epss":0.00202,"percentile":0.10288,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-8732","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8732","cwe":"CWE-674","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":["2.12.7+dfsg+really2.9.14-2.1+deb13u3"],"state":"fixed","available":[{"version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","date":"2026-07-12","kind":"first-observed"}]},"advisories":[],"risk":0.049490000000000006},"relatedVulnerabilities":[{"id":"CVE-2025-8732","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8732","namespace":"nvd:cpe","severity":"Low","urls":["https://drive.google.com/file/d/1woIeYVcSQB_NwfEhaVnX6MedpWJ_nqWl/view?usp=drive_link","https://gitlab.gnome.org/GNOME/libxml2/-/issues/958","https://gitlab.gnome.org/GNOME/libxml2/-/issues/958#note_2505853","https://vuldb.com/?ctiid.319228","https://vuldb.com/?id.319228","https://vuldb.com/?submit.622285","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that \"[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all.\"","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8732","epss":0.00202,"percentile":0.10288,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-8732","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8732","cwe":"CWE-674","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-8732","versionConstraint":"< 2.12.7+dfsg+really2.9.14-2.1+deb13u3 (deb)"},"fix":{"suggestedVersion":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"}}],"artifact":{"id":"07fee9125970d2ca","name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2007-5686","dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-5686","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.","cvss":[],"epss":[{"cve":"CVE-2007-5686","epss":0.00942,"percentile":0.57023,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0471},"relatedVulnerabilities":[{"id":"CVE-2007-5686","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-5686","namespace":"nvd:cpe","severity":"Medium","urls":["http://secunia.com/advisories/27215","http://www.securityfocus.com/archive/1/482129/100/100/threaded","http://www.securityfocus.com/archive/1/482857/100/0/threaded","http://www.securityfocus.com/bid/26048","http://www.vupen.com/english/advisories/2007/3474","https://issues.rpath.com/browse/RPL-1825"],"description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:C/I:N/A:N","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2007-5686","epss":0.00942,"percentile":0.57023,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2007-5686","versionConstraint":"none (unknown)"}}],"artifact":{"id":"78a386fd7b15051b","name":"login.defs","version":"1:4.17.4-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.postinst"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:login.defs:login.defs:1\\:4.17.4-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login.defs@1%3A4.17.4-2?arch=all&distro=debian-13.5&upstream=shadow","upstreams":[{"name":"shadow"}]}},{"vulnerability":{"id":"CVE-2007-5686","dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-5686","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.","cvss":[],"epss":[{"cve":"CVE-2007-5686","epss":0.00942,"percentile":0.57023,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0471},"relatedVulnerabilities":[{"id":"CVE-2007-5686","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-5686","namespace":"nvd:cpe","severity":"Medium","urls":["http://secunia.com/advisories/27215","http://www.securityfocus.com/archive/1/482129/100/100/threaded","http://www.securityfocus.com/archive/1/482857/100/0/threaded","http://www.securityfocus.com/bid/26048","http://www.vupen.com/english/advisories/2007/3474","https://issues.rpath.com/browse/RPL-1825"],"description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:C/I:N/A:N","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2007-5686","epss":0.00942,"percentile":0.57023,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2007-5686","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dae81fa9c3e5095f","name":"passwd","version":"1:4.17.4-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:passwd:passwd:1\\:4.17.4-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/passwd@1%3A4.17.4-2?arch=amd64&distro=debian-13.5&upstream=shadow","upstreams":[{"name":"shadow"}]}},{"vulnerability":{"id":"CVE-2026-24515","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24515","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24515","epss":0.0017,"percentile":0.06638,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24515","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04675},"relatedVulnerabilities":[{"id":"CVE-2026-24515","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24515","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/libexpat/libexpat/pull/1131","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24515","epss":0.0017,"percentile":0.06638,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-24515","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"expat","version":"2.7.1-2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-24515","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40642c4887673d7","name":"libexpat1","version":"2.7.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.7.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.7.1-2?arch=amd64&distro=debian-13.5&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2023-51103","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51103","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c.","cvss":[],"epss":[{"cve":"CVE-2023-51103","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51103","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.045700000000000005},"relatedVulnerabilities":[{"id":"CVE-2023-51103","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51103","namespace":"nvd:cpe","severity":"High","urls":["http://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=f1b5f87edd2675d5c79301e4ef2e1139f67f904b","https://bugs.ghostscript.com/show_bug.cgi?id=707620","https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md"],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51103","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51103","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-51103","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6de3a4b2ce25dd7","name":"libmupdf25.1","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.list"},{"path":"/var/lib/dpkg/info/libmupdf25.1.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.shlibs"},{"path":"/var/lib/dpkg/info/libmupdf25.1.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.symbols"},{"path":"/var/lib/dpkg/info/libmupdf25.1.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmupdf25.1:libmupdf25.1:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmupdf25.1@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2023-51104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51104","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero.","cvss":[],"epss":[{"cve":"CVE-2023-51104","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51104","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.045700000000000005},"relatedVulnerabilities":[{"id":"CVE-2023-51104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51104","namespace":"nvd:cpe","severity":"High","urls":["http://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=0c06a4e51519515615f6ab2d5b1f25da6771e1f4","https://bugs.ghostscript.com/show_bug.cgi?id=707621","https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md"],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51104","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51104","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-51104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6de3a4b2ce25dd7","name":"libmupdf25.1","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.list"},{"path":"/var/lib/dpkg/info/libmupdf25.1.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.shlibs"},{"path":"/var/lib/dpkg/info/libmupdf25.1.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.symbols"},{"path":"/var/lib/dpkg/info/libmupdf25.1.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmupdf25.1:libmupdf25.1:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmupdf25.1@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2023-51105","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51105","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.","cvss":[],"epss":[{"cve":"CVE-2023-51105","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51105","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.045700000000000005},"relatedVulnerabilities":[{"id":"CVE-2023-51105","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51105","namespace":"nvd:cpe","severity":"High","urls":["http://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=cee86dc519d5270a3b96476ad15809ceace64a26","https://bugs.ghostscript.com/show_bug.cgi?id=707622","https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md"],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51105","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51105","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-51105","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6de3a4b2ce25dd7","name":"libmupdf25.1","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.list"},{"path":"/var/lib/dpkg/info/libmupdf25.1.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.shlibs"},{"path":"/var/lib/dpkg/info/libmupdf25.1.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.symbols"},{"path":"/var/lib/dpkg/info/libmupdf25.1.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmupdf25.1:libmupdf25.1:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmupdf25.1@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2023-51103","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51103","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c.","cvss":[],"epss":[{"cve":"CVE-2023-51103","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51103","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.045700000000000005},"relatedVulnerabilities":[{"id":"CVE-2023-51103","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51103","namespace":"nvd:cpe","severity":"High","urls":["http://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=f1b5f87edd2675d5c79301e4ef2e1139f67f904b","https://bugs.ghostscript.com/show_bug.cgi?id=707620","https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md"],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51103","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51103","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-51103","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a8856e00526f091d","name":"python3-mupdf","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-mupdf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-mupdf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.list"},{"path":"/var/lib/dpkg/info/python3-mupdf.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.postinst"},{"path":"/var/lib/dpkg/info/python3-mupdf.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3-mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-mupdf@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2023-51104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51104","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero.","cvss":[],"epss":[{"cve":"CVE-2023-51104","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51104","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.045700000000000005},"relatedVulnerabilities":[{"id":"CVE-2023-51104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51104","namespace":"nvd:cpe","severity":"High","urls":["http://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=0c06a4e51519515615f6ab2d5b1f25da6771e1f4","https://bugs.ghostscript.com/show_bug.cgi?id=707621","https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md"],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51104","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51104","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-51104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a8856e00526f091d","name":"python3-mupdf","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-mupdf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-mupdf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.list"},{"path":"/var/lib/dpkg/info/python3-mupdf.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.postinst"},{"path":"/var/lib/dpkg/info/python3-mupdf.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3-mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-mupdf@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2023-51105","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51105","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.","cvss":[],"epss":[{"cve":"CVE-2023-51105","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51105","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.045700000000000005},"relatedVulnerabilities":[{"id":"CVE-2023-51105","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51105","namespace":"nvd:cpe","severity":"High","urls":["http://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=cee86dc519d5270a3b96476ad15809ceace64a26","https://bugs.ghostscript.com/show_bug.cgi?id=707622","https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md"],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51105","epss":0.00914,"percentile":0.5613,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51105","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-51105","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a8856e00526f091d","name":"python3-mupdf","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-mupdf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-mupdf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.list"},{"path":"/var/lib/dpkg/info/python3-mupdf.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.postinst"},{"path":"/var/lib/dpkg/info/python3-mupdf.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3-mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-mupdf@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2025-29070","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-29070","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because \"this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation.\"","cvss":[],"epss":[{"cve":"CVE-2025-29070","epss":0.00907,"percentile":0.5588,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-29070","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04535},"relatedVulnerabilities":[{"id":"CVE-2025-29070","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-29070","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/mm2/Little-CMS/issues/475","https://github.com/mm2/Little-CMS/issues/475#issuecomment-2696785063"],"description":"A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because \"this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation.\"","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-29070","epss":0.00907,"percentile":0.5588,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-29070","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"lcms2","version":"2.16-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-29070","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df3612de9a9fdeb4","name":"liblcms2-2","version":"2.16-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblcms2-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblcms2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblcms2-2:liblcms2-2:2.16-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:liblcms2-2:liblcms2_2:2.16-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:liblcms2_2:liblcms2-2:2.16-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:liblcms2_2:liblcms2_2:2.16-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:liblcms2:liblcms2-2:2.16-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:liblcms2:liblcms2_2:2.16-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblcms2-2@2.16-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=lcms2","upstreams":[{"name":"lcms2"}]}},{"vulnerability":{"id":"CVE-2024-26458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.52994,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04075},"relatedVulnerabilities":[{"id":"CVE-2024-26458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.52994,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1233a8cb20b5da22","name":"libgssapi-krb5-2","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.52994,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04075},"relatedVulnerabilities":[{"id":"CVE-2024-26458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.52994,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34c33399cc1862e4","name":"libk5crypto3","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libk5crypto3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.52994,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04075},"relatedVulnerabilities":[{"id":"CVE-2024-26458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.52994,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34b3a0e5c1bc108a","name":"libkrb5-3","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5-3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.52994,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04075},"relatedVulnerabilities":[{"id":"CVE-2024-26458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.52994,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"54c1c867e4d0ece0","name":"libkrb5support0","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5support0@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2023-46361","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-46361","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.","cvss":[],"epss":[{"cve":"CVE-2023-46361","epss":0.00753,"percentile":0.50929,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-46361","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03765},"relatedVulnerabilities":[{"id":"CVE-2023-46361","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-46361","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Frank-Z7/z-vulnerabilitys/blob/main/jbig2dec-SEGV/jbig2dec-SEGV.md"],"description":"Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-46361","epss":0.00753,"percentile":0.50929,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-46361","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"jbig2dec","version":"0.20-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-46361","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3aea2e5950cacb25","name":"libjbig2dec0","version":"0.20-1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libjbig2dec0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libjbig2dec0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libjbig2dec0:libjbig2dec0:0.20-1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjbig2dec0@0.20-1%2Bb3?arch=amd64&distro=debian-13.5&upstream=jbig2dec%400.20-1","upstreams":[{"name":"jbig2dec","version":"0.20-1"}]}},{"vulnerability":{"id":"CVE-2017-11695","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-11695","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[],"epss":[{"cve":"CVE-2017-11695","epss":0.00736,"percentile":0.50351,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-11695","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.036800000000000006},"relatedVulnerabilities":[{"id":"CVE-2017-11695","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-11695","namespace":"nvd:cpe","severity":"High","urls":["http://packetstormsecurity.com/files/143735/NSS-Buffer-Overflows-Floating-Point-Exception.html","http://seclists.org/fulldisclosure/2017/Aug/17","http://www.geeknik.net/9brdqk6xu","http://www.securityfocus.com/bid/100345","http://www.securitytracker.com/id/1039153","https://security.gentoo.org/glsa/202003-37"],"description":"Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-11695","epss":0.00736,"percentile":0.50351,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-11695","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"nss","version":"2:3.110-1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-11695","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d66110c0ae26fe8f","name":"libnss3","version":"2:3.110-1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.110-1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.110-1%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2017-11698","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-11698","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[],"epss":[{"cve":"CVE-2017-11698","epss":0.00736,"percentile":0.50351,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-11698","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.036800000000000006},"relatedVulnerabilities":[{"id":"CVE-2017-11698","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-11698","namespace":"nvd:cpe","severity":"High","urls":["http://packetstormsecurity.com/files/143735/NSS-Buffer-Overflows-Floating-Point-Exception.html","http://seclists.org/fulldisclosure/2017/Aug/17","http://www.geeknik.net/9brdqk6xu","http://www.securityfocus.com/bid/100345","http://www.securitytracker.com/id/1039153","https://security.gentoo.org/glsa/202003-37"],"description":"Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-11698","epss":0.00736,"percentile":0.50351,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-11698","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"nss","version":"2:3.110-1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-11698","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d66110c0ae26fe8f","name":"libnss3","version":"2:3.110-1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.110-1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.110-1%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2017-11696","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-11696","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[],"epss":[{"cve":"CVE-2017-11696","epss":0.00736,"percentile":0.5035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-11696","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.036800000000000006},"relatedVulnerabilities":[{"id":"CVE-2017-11696","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-11696","namespace":"nvd:cpe","severity":"High","urls":["http://packetstormsecurity.com/files/143735/NSS-Buffer-Overflows-Floating-Point-Exception.html","http://seclists.org/fulldisclosure/2017/Aug/17","http://www.geeknik.net/9brdqk6xu","http://www.securityfocus.com/bid/100345","http://www.securitytracker.com/id/1039153","https://security.gentoo.org/glsa/202003-37"],"description":"Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-11696","epss":0.00736,"percentile":0.5035,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-11696","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"nss","version":"2:3.110-1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-11696","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d66110c0ae26fe8f","name":"libnss3","version":"2:3.110-1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.110-1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.110-1%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2023-51107","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51107","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence to determine the existence of a vulnerability or identify the affected product.","cvss":[],"epss":[{"cve":"CVE-2023-51107","epss":0.00707,"percentile":0.49285,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51107","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-51107","cwe":"CWE-369","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03535},"relatedVulnerabilities":[{"id":"CVE-2023-51107","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51107","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md"],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence to determine the existence of a vulnerability or identify the affected product.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51107","epss":0.00707,"percentile":0.49285,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51107","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-51107","cwe":"CWE-369","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-51107","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6de3a4b2ce25dd7","name":"libmupdf25.1","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.list"},{"path":"/var/lib/dpkg/info/libmupdf25.1.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.shlibs"},{"path":"/var/lib/dpkg/info/libmupdf25.1.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.symbols"},{"path":"/var/lib/dpkg/info/libmupdf25.1.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmupdf25.1:libmupdf25.1:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmupdf25.1@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2023-51107","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51107","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence to determine the existence of a vulnerability or identify the affected product.","cvss":[],"epss":[{"cve":"CVE-2023-51107","epss":0.00707,"percentile":0.49285,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51107","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-51107","cwe":"CWE-369","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03535},"relatedVulnerabilities":[{"id":"CVE-2023-51107","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51107","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md"],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence to determine the existence of a vulnerability or identify the affected product.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51107","epss":0.00707,"percentile":0.49285,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51107","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-51107","cwe":"CWE-369","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-51107","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a8856e00526f091d","name":"python3-mupdf","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-mupdf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-mupdf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.list"},{"path":"/var/lib/dpkg/info/python3-mupdf.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.postinst"},{"path":"/var/lib/dpkg/info/python3-mupdf.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3-mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-mupdf@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2023-51106","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51106","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero.","cvss":[],"epss":[{"cve":"CVE-2023-51106","epss":0.00707,"percentile":0.49284,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51106","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03535},"relatedVulnerabilities":[{"id":"CVE-2023-51106","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51106","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md"],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51106","epss":0.00707,"percentile":0.49284,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51106","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-51106","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6de3a4b2ce25dd7","name":"libmupdf25.1","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmupdf25.1.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.list"},{"path":"/var/lib/dpkg/info/libmupdf25.1.shlibs","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.shlibs"},{"path":"/var/lib/dpkg/info/libmupdf25.1.symbols","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.symbols"},{"path":"/var/lib/dpkg/info/libmupdf25.1.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmupdf25.1.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmupdf25.1:libmupdf25.1:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmupdf25.1@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2023-51106","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51106","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero.","cvss":[],"epss":[{"cve":"CVE-2023-51106","epss":0.00707,"percentile":0.49284,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51106","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03535},"relatedVulnerabilities":[{"id":"CVE-2023-51106","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51106","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md"],"description":"A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51106","epss":0.00707,"percentile":0.49284,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-51106","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"mupdf","version":"1.25.1+ds1-6+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-51106","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a8856e00526f091d","name":"python3-mupdf","version":"1.25.1+ds1-6+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3-mupdf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-mupdf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.list"},{"path":"/var/lib/dpkg/info/python3-mupdf.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.postinst"},{"path":"/var/lib/dpkg/info/python3-mupdf.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3-mupdf.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3-mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3-mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3_mupdf:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_mupdf:1.25.1\\+ds1-6\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-mupdf@1.25.1%2Bds1-6%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=mupdf","upstreams":[{"name":"mupdf"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03245},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d73c99dbc97f6ec0","name":"dirmngr","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/dirmngr@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03245},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ced4de0e43890bd3","name":"gnupg","version":"2.4.7-21+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gnupg:gnupg:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg@2.4.7-21%2Bdeb13u1?arch=all&distro=debian-13.5&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03245},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"deb1d413d83f82b8","name":"gnupg-l10n","version":"2.4.7-21+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-l10n@2.4.7-21%2Bdeb13u1?arch=all&distro=debian-13.5&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03245},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cd76d9c17a1cf27f","name":"gpg","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.list"},{"path":"/var/lib/dpkg/info/gpg.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.postinst"},{"path":"/var/lib/dpkg/info/gpg.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.postrm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpg:gpg:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03245},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2660f16d4b2ce1d7","name":"gpg-agent","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-agent@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03245},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c44d319fa06436ce","name":"gpgconf","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgconf@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:13","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03245},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.0011,"percentile":0.01502,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"321974a38b0687e6","name":"gpgsm","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgsm@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2023-37769","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-37769","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c.","cvss":[],"epss":[{"cve":"CVE-2023-37769","epss":0.00586,"percentile":0.44125,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-37769","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.029300000000000003},"relatedVulnerabilities":[{"id":"CVE-2023-37769","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-37769","namespace":"nvd:cpe","severity":"Medium","urls":["https://gitlab.freedesktop.org/pixman/pixman/-/issues/76"],"description":"stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-37769","epss":0.00586,"percentile":0.44125,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-37769","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"pixman","version":"0.44.0-3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-37769","versionConstraint":"none (unknown)"}}],"artifact":{"id":"59d0838200510bf1","name":"libpixman-1-0","version":"0.44.0-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpixman-1-0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpixman-1-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpixman-1-0:libpixman-1-0:0.44.0-3:*:*:*:*:*:*:*","cpe:2.3:a:libpixman-1-0:libpixman_1_0:0.44.0-3:*:*:*:*:*:*:*","cpe:2.3:a:libpixman_1_0:libpixman-1-0:0.44.0-3:*:*:*:*:*:*:*","cpe:2.3:a:libpixman_1_0:libpixman_1_0:0.44.0-3:*:*:*:*:*:*:*","cpe:2.3:a:libpixman-1:libpixman-1-0:0.44.0-3:*:*:*:*:*:*:*","cpe:2.3:a:libpixman-1:libpixman_1_0:0.44.0-3:*:*:*:*:*:*:*","cpe:2.3:a:libpixman_1:libpixman-1-0:0.44.0-3:*:*:*:*:*:*:*","cpe:2.3:a:libpixman_1:libpixman_1_0:0.44.0-3:*:*:*:*:*:*:*","cpe:2.3:a:libpixman:libpixman-1-0:0.44.0-3:*:*:*:*:*:*:*","cpe:2.3:a:libpixman:libpixman_1_0:0.44.0-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpixman-1-0@0.44.0-3?arch=amd64&distro=debian-13.5&upstream=pixman","upstreams":[{"name":"pixman"}]}},{"vulnerability":{"id":"CVE-2021-4217","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-4217","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.","cvss":[],"epss":[{"cve":"CVE-2021-4217","epss":0.0057,"percentile":0.43389,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2021-4217","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2021-4217","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.028500000000000004},"relatedVulnerabilities":[{"id":"CVE-2021-4217","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4217","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2021-4217","https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1957077","https://bugzilla.redhat.com/show_bug.cgi?id=2044583"],"description":"A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-4217","epss":0.0057,"percentile":0.43389,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2021-4217","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2021-4217","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"unzip","version":"6.0-29"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2021-4217","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a2e068ac36d99078","name":"unzip","version":"6.0-29","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/unzip.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/unzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/unzip.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/unzip.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:unzip:unzip:6.0-29:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/unzip@6.0-29?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2017-11697","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-11697","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.","cvss":[],"epss":[{"cve":"CVE-2017-11697","epss":0.00523,"percentile":0.40879,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-11697","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02615},"relatedVulnerabilities":[{"id":"CVE-2017-11697","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-11697","namespace":"nvd:cpe","severity":"High","urls":["http://packetstormsecurity.com/files/143735/NSS-Buffer-Overflows-Floating-Point-Exception.html","http://seclists.org/fulldisclosure/2017/Aug/17","http://www.geeknik.net/9brdqk6xu","http://www.securityfocus.com/bid/100345","http://www.securitytracker.com/id/1039153","https://security.gentoo.org/glsa/202003-37"],"description":"The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-11697","epss":0.00523,"percentile":0.40879,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-11697","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"nss","version":"2:3.110-1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-11697","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d66110c0ae26fe8f","name":"libnss3","version":"2:3.110-1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.110-1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.110-1%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2026-9547","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9547","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.","cvss":[],"epss":[{"cve":"CVE-2026-9547","epss":0.00508,"percentile":0.39964,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.025400000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-9547","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9547","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-9547.html","https://curl.se/docs/CVE-2026-9547.json","https://hackerone.com/reports/3751712"],"description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9547","epss":0.00508,"percentile":0.39964,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9547","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-9547","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9547","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.","cvss":[],"epss":[{"cve":"CVE-2026-9547","epss":0.00508,"percentile":0.39964,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.025400000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-9547","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9547","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-9547.html","https://curl.se/docs/CVE-2026-9547.json","https://hackerone.com/reports/3751712"],"description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9547","epss":0.00508,"percentile":0.39964,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9547","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2021-4214","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-4214","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.","cvss":[],"epss":[{"cve":"CVE-2021-4214","epss":0.00505,"percentile":0.39847,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2021-4214","cwe":"CWE-120","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2021-4214","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02525},"relatedVulnerabilities":[{"id":"CVE-2021-4214","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4214","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2021-4214","https://bugzilla.redhat.com/show_bug.cgi?id=2043393","https://github.com/glennrp/libpng/issues/302","https://security-tracker.debian.org/tracker/CVE-2021-4214","https://security.netapp.com/advisory/ntap-20221020-0001/"],"description":"A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-4214","epss":0.00505,"percentile":0.39847,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2021-4214","cwe":"CWE-120","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2021-4214","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libpng1.6","version":"1.6.48-1+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2021-4214","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cea4bcf3539a1df3","name":"libpng16-16t64","version":"1.6.48-1+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpng16-16t64:libpng16-16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16t64:libpng16_16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16-16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16_16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpng16-16t64@1.6.48-1%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libpng1.6","upstreams":[{"name":"libpng1.6"}]}},{"vulnerability":{"id":"CVE-2013-4392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[],"epss":[{"cve":"CVE-2013-4392","epss":0.00472,"percentile":0.37793,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.023600000000000003},"relatedVulnerabilities":[{"id":"CVE-2013-4392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","namespace":"nvd:cpe","severity":"Low","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":3.4,"impactScore":5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-4392","epss":0.00472,"percentile":0.37793,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7b65794238bbb047","name":"libsystemd0","version":"257.13-1~deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64&distro=debian-13.5&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2013-4392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[],"epss":[{"cve":"CVE-2013-4392","epss":0.00472,"percentile":0.37793,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.023600000000000003},"relatedVulnerabilities":[{"id":"CVE-2013-4392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","namespace":"nvd:cpe","severity":"Low","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":3.4,"impactScore":5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-4392","epss":0.00472,"percentile":0.37793,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7eaf5069148b010f","name":"libudev1","version":"257.13-1~deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libudev1:libudev1:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64&distro=debian-13.5&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2025-15079","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15079","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.","cvss":[],"epss":[{"cve":"CVE-2025-15079","epss":0.00457,"percentile":0.36821,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.022850000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-15079","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15079","epss":0.00457,"percentile":0.36821,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-15079","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15079","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.","cvss":[],"epss":[{"cve":"CVE-2025-15079","epss":0.00457,"percentile":0.36821,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.022850000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-15079","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15079","epss":0.00457,"percentile":0.36821,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021500000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"943eceb0b62d5077","name":"bsdutils","version":"1:2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021500000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"789c9c1c32d67963","name":"libblkid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021500000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1c14db01751ab35","name":"liblastlog2-2","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021500000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f2906fa44fcde82e","name":"libmount1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021500000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6bc0f11ba93c58e0","name":"libsmartcols1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021500000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b9befafdeaa440fd","name":"libuuid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021500000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dc55662712ce7274","name":"login","version":"1:4.16.0-2+really2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021500000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0adc54d0e11f3b69","name":"mount","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021500000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.0043,"percentile":0.34884,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3accc11c0ad101fe","name":"util-linux","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-15224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15224","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.","cvss":[],"epss":[{"cve":"CVE-2025-15224","epss":0.00413,"percentile":0.33485,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02065},"relatedVulnerabilities":[{"id":"CVE-2025-15224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15224","namespace":"nvd:cpe","severity":"Low","urls":["https://curl.se/docs/CVE-2025-15224.html","https://curl.se/docs/CVE-2025-15224.json","https://hackerone.com/reports/3480925","http://www.openwall.com/lists/oss-security/2026/01/07/7"],"description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15224","epss":0.00413,"percentile":0.33485,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-15224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15224","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.","cvss":[],"epss":[{"cve":"CVE-2025-15224","epss":0.00413,"percentile":0.33485,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02065},"relatedVulnerabilities":[{"id":"CVE-2025-15224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15224","namespace":"nvd:cpe","severity":"Low","urls":["https://curl.se/docs/CVE-2025-15224.html","https://curl.se/docs/CVE-2025-15224.json","https://hackerone.com/reports/3480925","http://www.openwall.com/lists/oss-security/2026/01/07/7"],"description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15224","epss":0.00413,"percentile":0.33485,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-10966","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10966","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms.  This prevents curl from detecting MITM attackers and more.","cvss":[],"epss":[{"cve":"CVE-2025-10966","epss":0.0039,"percentile":0.31273,"date":"2026-07-18"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0195},"relatedVulnerabilities":[{"id":"CVE-2025-10966","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10966","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-10966.html","https://curl.se/docs/CVE-2025-10966.json","https://hackerone.com/reports/3355218","http://www.openwall.com/lists/oss-security/2025/11/05/2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://github.com/curl/curl/commit/b011e3fcfb06d6c0278595ee2ee297036fbe9793"],"description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10966","epss":0.0039,"percentile":0.31273,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-10966","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-10966","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10966","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms.  This prevents curl from detecting MITM attackers and more.","cvss":[],"epss":[{"cve":"CVE-2025-10966","epss":0.0039,"percentile":0.31273,"date":"2026-07-18"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0195},"relatedVulnerabilities":[{"id":"CVE-2025-10966","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10966","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-10966.html","https://curl.se/docs/CVE-2025-10966.json","https://hackerone.com/reports/3355218","http://www.openwall.com/lists/oss-security/2025/11/05/2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://github.com/curl/curl/commit/b011e3fcfb06d6c0278595ee2ee297036fbe9793"],"description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10966","epss":0.0039,"percentile":0.31273,"date":"2026-07-18"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-10966","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2013-4472","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4472","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.","cvss":[],"epss":[{"cve":"CVE-2013-4472","epss":0.00367,"percentile":0.28921,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2013-4472","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01835},"relatedVulnerabilities":[{"id":"CVE-2013-4472","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4472","namespace":"nvd:cpe","severity":"Low","urls":["http://osvdb.org/99064","http://poppler.freedesktop.org/releases.html","http://seclists.org/oss-sec/2013/q4/181","http://seclists.org/oss-sec/2013/q4/183"],"description":"The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":3.3,"exploitabilityScore":3.4,"impactScore":5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-4472","epss":0.00367,"percentile":0.28921,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2013-4472","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"poppler","version":"25.03.0-5+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2013-4472","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f9378ee2c5fb55fb","name":"libpoppler147","version":"25.03.0-5+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpoppler147:libpoppler147:25.03.0-5\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpoppler147@25.03.0-5%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=poppler","upstreams":[{"name":"poppler"}]}},{"vulnerability":{"id":"CVE-2023-31439","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31439","epss":0.00352,"percentile":0.27476,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0176},"relatedVulnerabilities":[{"id":"CVE-2023-31439","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31439","epss":0.00352,"percentile":0.27476,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7b65794238bbb047","name":"libsystemd0","version":"257.13-1~deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64&distro=debian-13.5&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31439","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31439","epss":0.00352,"percentile":0.27476,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0176},"relatedVulnerabilities":[{"id":"CVE-2023-31439","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31439","epss":0.00352,"percentile":0.27476,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7eaf5069148b010f","name":"libudev1","version":"257.13-1~deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libudev1:libudev1:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64&distro=debian-13.5&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2017-14159","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-14159","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.","cvss":[],"epss":[{"cve":"CVE-2017-14159","epss":0.00349,"percentile":0.27161,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-14159","cwe":"CWE-665","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2017-14159","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-14159","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openldap.org/its/index.cgi?findid=8703","https://www.oracle.com/security-alerts/cpuapr2022.html"],"description":"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-14159","epss":0.00349,"percentile":0.27161,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-14159","cwe":"CWE-665","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-14159","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34614e72922d8e4b","name":"libldap2","version":"2.6.10+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.5&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2017-18018","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-18018","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.","cvss":[],"epss":[{"cve":"CVE-2017-18018","epss":0.00348,"percentile":0.27079,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-18018","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2017-18018","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0174},"relatedVulnerabilities":[{"id":"CVE-2017-18018","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18018","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.gnu.org/archive/html/coreutils/2017-12/msg00045.html"],"description":"In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-18018","epss":0.00348,"percentile":0.27079,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2017-18018","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2017-18018","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"coreutils","version":"9.7-3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2017-18018","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ffff8c91932545cc","name":"coreutils","version":"9.7-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:coreutils:coreutils:9.7-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/coreutils@9.7-3?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2023-31437","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31437","epss":0.00344,"percentile":0.26655,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0172},"relatedVulnerabilities":[{"id":"CVE-2023-31437","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31437","epss":0.00344,"percentile":0.26655,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7b65794238bbb047","name":"libsystemd0","version":"257.13-1~deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64&distro=debian-13.5&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31437","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31437","epss":0.00344,"percentile":0.26655,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0172},"relatedVulnerabilities":[{"id":"CVE-2023-31437","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31437","epss":0.00344,"percentile":0.26655,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7eaf5069148b010f","name":"libudev1","version":"257.13-1~deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libudev1:libudev1:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64&distro=debian-13.5&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31438","epss":0.00328,"percentile":0.24942,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0164},"relatedVulnerabilities":[{"id":"CVE-2023-31438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31438","epss":0.00328,"percentile":0.24942,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7b65794238bbb047","name":"libsystemd0","version":"257.13-1~deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64&distro=debian-13.5&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31438","epss":0.00328,"percentile":0.24942,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0164},"relatedVulnerabilities":[{"id":"CVE-2023-31438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31438","epss":0.00328,"percentile":0.24942,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7eaf5069148b010f","name":"libudev1","version":"257.13-1~deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libudev1:libudev1:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64&distro=debian-13.5&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d73c99dbc97f6ec0","name":"dirmngr","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/dirmngr@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ced4de0e43890bd3","name":"gnupg","version":"2.4.7-21+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gnupg:gnupg:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg@2.4.7-21%2Bdeb13u1?arch=all&distro=debian-13.5&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"deb1d413d83f82b8","name":"gnupg-l10n","version":"2.4.7-21+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-l10n@2.4.7-21%2Bdeb13u1?arch=all&distro=debian-13.5&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cd76d9c17a1cf27f","name":"gpg","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.list"},{"path":"/var/lib/dpkg/info/gpg.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.postinst"},{"path":"/var/lib/dpkg/info/gpg.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.postrm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpg:gpg:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2660f16d4b2ce1d7","name":"gpg-agent","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-agent@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c44d319fa06436ce","name":"gpgconf","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgconf@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21225,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"321974a38b0687e6","name":"gpgsm","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgsm@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]}},{"vulnerability":{"id":"CVE-2022-24106","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-24106","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.","cvss":[],"epss":[{"cve":"CVE-2022-24106","epss":0.00292,"percentile":0.21108,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-24106","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0146},"relatedVulnerabilities":[{"id":"CVE-2022-24106","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24106","namespace":"nvd:cpe","severity":"High","urls":["http://www.xpdfreader.com/security-fixes.html","https://dl.xpdfreader.com/xpdf-4.04.tar.gz"],"description":"In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-24106","epss":0.00292,"percentile":0.21108,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2022-24106","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"poppler","version":"25.03.0-5+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2022-24106","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f9378ee2c5fb55fb","name":"libpoppler147","version":"25.03.0-5+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpoppler147:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpoppler147:libpoppler147:25.03.0-5\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpoppler147@25.03.0-5%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=poppler","upstreams":[{"name":"poppler"}]}},{"vulnerability":{"id":"CVE-2025-8177","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8177","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.","cvss":[],"epss":[{"cve":"CVE-2025-8177","epss":0.00271,"percentile":0.1892,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-8177","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8177","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.013550000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-8177","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8177","namespace":"nvd:cpe","severity":"High","urls":["http://www.libtiff.org/","https://gitlab.com/libtiff/libtiff/-/commit/e8c9d6c616b19438695fd829e58ae4fde5bfbc22","https://gitlab.com/libtiff/libtiff/-/issues/715","https://gitlab.com/libtiff/libtiff/-/merge_requests/737","https://vuldb.com/?ctiid.317591","https://vuldb.com/?id.317591","https://vuldb.com/?submit.621797"],"description":"A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8177","epss":0.00271,"percentile":0.1892,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-8177","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8177","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tiff","version":"4.7.0-3+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-8177","versionConstraint":"none (unknown)"}}],"artifact":{"id":"632b90e0e50cde2d","name":"libtiff6","version":"4.7.0-3+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-11850","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[],"epss":[{"cve":"CVE-2026-11850","epss":0.00261,"percentile":0.17628,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01305},"relatedVulnerabilities":[{"id":"CVE-2026-11850","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":0.8,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11850","epss":0.00261,"percentile":0.17628,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1233a8cb20b5da22","name":"libgssapi-krb5-2","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2026-11850","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[],"epss":[{"cve":"CVE-2026-11850","epss":0.00261,"percentile":0.17628,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01305},"relatedVulnerabilities":[{"id":"CVE-2026-11850","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":0.8,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11850","epss":0.00261,"percentile":0.17628,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34c33399cc1862e4","name":"libk5crypto3","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libk5crypto3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2026-11850","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[],"epss":[{"cve":"CVE-2026-11850","epss":0.00261,"percentile":0.17628,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01305},"relatedVulnerabilities":[{"id":"CVE-2026-11850","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":0.8,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11850","epss":0.00261,"percentile":0.17628,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34b3a0e5c1bc108a","name":"libkrb5-3","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5-3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2026-11850","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[],"epss":[{"cve":"CVE-2026-11850","epss":0.00261,"percentile":0.17628,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01305},"relatedVulnerabilities":[{"id":"CVE-2026-11850","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":0.8,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11850","epss":0.00261,"percentile":0.17628,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"}}],"artifact":{"id":"54c1c867e4d0ece0","name":"libkrb5support0","version":"1.21.3-5+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5support0@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2025-61144","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-61144","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.","cvss":[],"epss":[{"cve":"CVE-2025-61144","epss":0.00253,"percentile":0.1662,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-61144","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61144","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012650000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-61144","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61144","namespace":"nvd:cpe","severity":"High","urls":["https://gist.github.com/optionGo/5ad17e96a0a40f03578dd6c9f8645952","https://gitlab.com/libtiff/libtiff/-/commit/09f53a86cf26dfd961925227e59e180db617f26d","https://gitlab.com/libtiff/libtiff/-/commit/88cf9dbb48f6e172629795ecffae35d5052f68aa","https://gitlab.com/libtiff/libtiff/-/issues/740","https://gitlab.com/libtiff/libtiff/-/merge_requests/757"],"description":"libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.4,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61144","epss":0.00253,"percentile":0.1662,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-61144","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61144","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tiff","version":"4.7.0-3+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-61144","versionConstraint":"none (unknown)"}}],"artifact":{"id":"632b90e0e50cde2d","name":"libtiff6","version":"4.7.0-3+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14834,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-8176","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8176","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8176","epss":0.00238,"percentile":0.14749,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-8176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8176","cwe":"CWE-416","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-8176","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8176","namespace":"nvd:cpe","severity":"High","urls":["http://www.libtiff.org/","https://gitlab.com/libtiff/libtiff/-/commit/fe10872e53efba9cc36c66ac4ab3b41a839d5172","https://gitlab.com/libtiff/libtiff/-/issues/707","https://gitlab.com/libtiff/libtiff/-/merge_requests/727","https://vuldb.com/?ctiid.317590","https://vuldb.com/?id.317590","https://vuldb.com/?submit.621796"],"description":"A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8176","epss":0.00238,"percentile":0.14749,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-8176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8176","cwe":"CWE-416","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tiff","version":"4.7.0-3+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-8176","versionConstraint":"none (unknown)"}}],"artifact":{"id":"632b90e0e50cde2d","name":"libtiff6","version":"4.7.0-3+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-4360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4360","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.","cvss":[],"epss":[{"cve":"CVE-2026-4360","epss":0.00235,"percentile":0.14343,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.011750000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-4360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4360","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0","https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301","https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a","https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44","https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e","https://github.com/python/cpython/issues/151987","https://github.com/python/cpython/pull/151988","https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"],"description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4360","epss":0.00235,"percentile":0.14343,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-4360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-4360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4360","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.","cvss":[],"epss":[{"cve":"CVE-2026-4360","epss":0.00235,"percentile":0.14343,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.011750000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-4360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4360","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0","https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301","https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a","https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44","https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e","https://github.com/python/cpython/issues/151987","https://github.com/python/cpython/pull/151988","https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"],"description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4360","epss":0.00235,"percentile":0.14343,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-4360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-4360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4360","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.","cvss":[],"epss":[{"cve":"CVE-2026-4360","epss":0.00235,"percentile":0.14343,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.011750000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-4360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4360","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0","https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301","https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a","https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44","https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e","https://github.com/python/cpython/issues/151987","https://github.com/python/cpython/pull/151988","https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"],"description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4360","epss":0.00235,"percentile":0.14343,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-4360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-4360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4360","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.","cvss":[],"epss":[{"cve":"CVE-2026-4360","epss":0.00235,"percentile":0.14343,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.011750000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-4360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4360","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0","https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301","https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a","https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44","https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e","https://github.com/python/cpython/issues/151987","https://github.com/python/cpython/pull/151988","https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"],"description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4360","epss":0.00235,"percentile":0.14343,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-4360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-4360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4360","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.","cvss":[],"epss":[{"cve":"CVE-2026-4360","epss":0.00235,"percentile":0.14343,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.011750000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-4360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4360","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0","https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301","https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a","https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44","https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e","https://github.com/python/cpython/issues/151987","https://github.com/python/cpython/pull/151988","https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"],"description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4360","epss":0.00235,"percentile":0.14343,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-4360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-5278","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5278","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.","cvss":[],"epss":[{"cve":"CVE-2025-5278","epss":0.00224,"percentile":0.13042,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-5278","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0112},"relatedVulnerabilities":[{"id":"CVE-2025-5278","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5278","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:28911","https://access.redhat.com/errata/RHSA-2026:33124","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:33612","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/security/cve/CVE-2025-5278","https://bugzilla.redhat.com/show_bug.cgi?id=2368764","https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507","http://www.openwall.com/lists/oss-security/2025/05/27/2","http://www.openwall.com/lists/oss-security/2025/05/29/1","http://www.openwall.com/lists/oss-security/2025/05/29/2","https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14","https://security-tracker.debian.org/tracker/CVE-2025-5278"],"description":"A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"exploitabilityScore":1.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5278","epss":0.00224,"percentile":0.13042,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-5278","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"coreutils","version":"9.7-3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-5278","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ffff8c91932545cc","name":"coreutils","version":"9.7-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:coreutils:coreutils:9.7-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/coreutils@9.7-3?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-8534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8534","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that \"[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. \"rD\") option is used.\"","cvss":[],"epss":[{"cve":"CVE-2025-8534","epss":0.00182,"percentile":0.07943,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-8534","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8534","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0091},"relatedVulnerabilities":[{"id":"CVE-2025-8534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8534","namespace":"nvd:cpe","severity":"Low","urls":["http://www.libtiff.org/","https://drive.google.com/file/d/15JPA3kLYiYD-nRNJ8y8HmnYjhv9NE7k6/view?usp=drive_link","https://gitlab.com/libtiff/libtiff/-/commit/6ba36f159fd396ad11bf6b7874554197736ecc8b","https://gitlab.com/libtiff/libtiff/-/issues/718","https://gitlab.com/libtiff/libtiff/-/merge_requests/746","https://vuldb.com/?ctiid.318664","https://vuldb.com/?id.318664","https://vuldb.com/?submit.617831"],"description":"A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that \"[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. \"rD\") option is used.\"","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.1},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:H/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1,"exploitabilityScore":1.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8534","epss":0.00182,"percentile":0.07943,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-8534","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8534","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tiff","version":"4.7.0-3+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-8534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"632b90e0e50cde2d","name":"libtiff6","version":"4.7.0-3+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008950000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"943eceb0b62d5077","name":"bsdutils","version":"1:2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008950000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"789c9c1c32d67963","name":"libblkid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008950000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1c14db01751ab35","name":"liblastlog2-2","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008950000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f2906fa44fcde82e","name":"libmount1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008950000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6bc0f11ba93c58e0","name":"libsmartcols1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008950000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b9befafdeaa440fd","name":"libuuid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008950000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dc55662712ce7274","name":"login","version":"1:4.16.0-2+really2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008950000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0adc54d0e11f3b69","name":"mount","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008950000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00179,"percentile":0.07595,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3accc11c0ad101fe","name":"util-linux","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-11979","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11979","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.  This issue has been fixed in the commit c2e233fc.  NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.","cvss":[],"epss":[{"cve":"CVE-2026-11979","epss":0.00148,"percentile":0.04458,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11979","cwe":"CWE-121","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.007400000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-11979","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11979","namespace":"nvd:cpe","severity":"High","urls":["https://cert.pl/en/posts/2026/06/CVE-2026-11979","https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e"],"description":"libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.\nBy supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.\nSuccessful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.\n\nThis issue has been fixed in the commit c2e233fc.\n\nNOTE:\nThe maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11979","epss":0.00148,"percentile":0.04458,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11979","cwe":"CWE-121","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11979","versionConstraint":"none (unknown)"}}],"artifact":{"id":"07fee9125970d2ca","name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00136,"percentile":0.03457,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.006800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00136,"percentile":0.03457,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00136,"percentile":0.03457,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.006800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00136,"percentile":0.03457,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00136,"percentile":0.03457,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.006800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00136,"percentile":0.03457,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00136,"percentile":0.03457,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.006800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00136,"percentile":0.03457,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00136,"percentile":0.03457,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.006800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00136,"percentile":0.03457,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]}},{"vulnerability":{"id":"CVE-2025-61145","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-61145","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.","cvss":[],"epss":[{"cve":"CVE-2025-61145","epss":0.00131,"percentile":0.03078,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-61145","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61145","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00655},"relatedVulnerabilities":[{"id":"CVE-2025-61145","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61145","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/optionGo/062f109569196dbffd8ac12020b42289","https://gitlab.com/libtiff/libtiff/-/issues/736","https://gitlab.com/libtiff/libtiff/-/merge_requests/753"],"description":"libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61145","epss":0.00131,"percentile":0.03078,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-61145","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61145","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tiff","version":"4.7.0-3+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-61145","versionConstraint":"none (unknown)"}}],"artifact":{"id":"632b90e0e50cde2d","name":"libtiff6","version":"4.7.0-3+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-22185","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-22185","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.","cvss":[],"epss":[{"cve":"CVE-2026-22185","epss":0.00127,"percentile":0.02719,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-22185","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0063500000000000015},"relatedVulnerabilities":[{"id":"CVE-2026-22185","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22185","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.openldap.org/show_bug.cgi?id=10421","https://seclists.org/fulldisclosure/2026/Jan/5","https://seclists.org/fulldisclosure/2026/Jan/8","https://www.openldap.org/","https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"],"description":"OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-22185","epss":0.00127,"percentile":0.02719,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-22185","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-22185","versionConstraint":"none (unknown)"}}],"artifact":{"id":"34614e72922d8e4b","name":"libldap2","version":"2.6.10+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.5&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2026-3713","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3713","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.","cvss":[],"epss":[{"cve":"CVE-2026-3713","epss":0.00126,"percentile":0.02622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3713","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-3713","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0063},"relatedVulnerabilities":[{"id":"CVE-2026-3713","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3713","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/biniamf/pocs/tree/main/pnm2png","https://github.com/pnggroup/libpng/","https://github.com/pnggroup/libpng/issues/794","https://vuldb.com/?ctiid.349658","https://vuldb.com/?id.349658","https://vuldb.com/?submit.761996"],"description":"A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3713","epss":0.00126,"percentile":0.02622,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-3713","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-3713","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"libpng1.6","version":"1.6.48-1+deb13u5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-3713","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cea4bcf3539a1df3","name":"libpng16-16t64","version":"1.6.48-1+deb13u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpng16-16t64:libpng16-16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16t64:libpng16_16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16-16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16_16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpng16-16t64@1.6.48-1%2Bdeb13u5?arch=amd64&distro=debian-13.5&upstream=libpng1.6","upstreams":[{"name":"libpng1.6"}]}},{"vulnerability":{"id":"CVE-2025-61143","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-61143","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.","cvss":[],"epss":[{"cve":"CVE-2025-61143","epss":0.00113,"percentile":0.01689,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-61143","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61143","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00565},"relatedVulnerabilities":[{"id":"CVE-2025-61143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61143","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/optionGo/9c024cd8e7b131463b84dc60af9bb0aa","https://gitlab.com/libtiff/libtiff/-/issues/737","https://gitlab.com/libtiff/libtiff/-/merge_requests/755"],"description":"libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61143","epss":0.00113,"percentile":0.01689,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-61143","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61143","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tiff","version":"4.7.0-3+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-61143","versionConstraint":"none (unknown)"}}],"artifact":{"id":"632b90e0e50cde2d","name":"libtiff6","version":"4.7.0-3+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2025-14017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14017","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers.  Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.","cvss":[],"epss":[{"cve":"CVE-2025-14017","epss":0.00106,"percentile":0.01308,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0053},"relatedVulnerabilities":[{"id":"CVE-2025-14017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14017","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-14017.html","https://curl.se/docs/CVE-2025-14017.json","http://www.openwall.com/lists/oss-security/2026/01/07/3"],"description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14017","epss":0.00106,"percentile":0.01308,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df2c1b7a6202cff3","name":"libcurl3t64-gnutls","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-14017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14017","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers.  Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.","cvss":[],"epss":[{"cve":"CVE-2025-14017","epss":0.00106,"percentile":0.01308,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0053},"relatedVulnerabilities":[{"id":"CVE-2025-14017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14017","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-14017.html","https://curl.se/docs/CVE-2025-14017.json","http://www.openwall.com/lists/oss-security/2026/01/07/3"],"description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14017","epss":0.00106,"percentile":0.01308,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"curl","version":"8.14.1-2+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-14017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e807e29b884d567a","name":"libcurl4t64","version":"8.14.1-2+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-53612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53612","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53612","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"none (unknown)"}}],"artifact":{"id":"943eceb0b62d5077","name":"bsdutils","version":"1:2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"943eceb0b62d5077","name":"bsdutils","version":"1:2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-53614","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53614","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53614","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"none (unknown)"}}],"artifact":{"id":"943eceb0b62d5077","name":"bsdutils","version":"1:2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"943eceb0b62d5077","name":"bsdutils","version":"1:2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-53612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53612","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53612","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"none (unknown)"}}],"artifact":{"id":"789c9c1c32d67963","name":"libblkid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"789c9c1c32d67963","name":"libblkid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53614","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53614","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53614","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"none (unknown)"}}],"artifact":{"id":"789c9c1c32d67963","name":"libblkid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"789c9c1c32d67963","name":"libblkid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53612","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53612","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1c14db01751ab35","name":"liblastlog2-2","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1c14db01751ab35","name":"liblastlog2-2","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53614","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53614","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53614","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1c14db01751ab35","name":"liblastlog2-2","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1c14db01751ab35","name":"liblastlog2-2","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53612","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53612","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f2906fa44fcde82e","name":"libmount1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f2906fa44fcde82e","name":"libmount1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53614","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53614","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53614","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f2906fa44fcde82e","name":"libmount1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f2906fa44fcde82e","name":"libmount1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53612","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53612","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6bc0f11ba93c58e0","name":"libsmartcols1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6bc0f11ba93c58e0","name":"libsmartcols1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53614","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53614","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53614","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6bc0f11ba93c58e0","name":"libsmartcols1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6bc0f11ba93c58e0","name":"libsmartcols1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-36849","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-36849","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-36849","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"tiff","version":"4.7.0-3+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-36849","versionConstraint":"none (unknown)"}}],"artifact":{"id":"632b90e0e50cde2d","name":"libtiff6","version":"4.7.0-3+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-53612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53612","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53612","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b9befafdeaa440fd","name":"libuuid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b9befafdeaa440fd","name":"libuuid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53614","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53614","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53614","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b9befafdeaa440fd","name":"libuuid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b9befafdeaa440fd","name":"libuuid1","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53612","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53612","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dc55662712ce7274","name":"login","version":"1:4.16.0-2+really2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dc55662712ce7274","name":"login","version":"1:4.16.0-2+really2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-53614","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53614","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53614","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dc55662712ce7274","name":"login","version":"1:4.16.0-2+really2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dc55662712ce7274","name":"login","version":"1:4.16.0-2+really2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/login.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux%402.41-5","upstreams":[{"name":"util-linux","version":"2.41-5"}]}},{"vulnerability":{"id":"CVE-2026-53612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53612","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53612","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0adc54d0e11f3b69","name":"mount","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0adc54d0e11f3b69","name":"mount","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53614","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53614","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53614","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0adc54d0e11f3b69","name":"mount","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0adc54d0e11f3b69","name":"mount","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.5&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53612","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53612","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3accc11c0ad101fe","name":"util-linux","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3accc11c0ad101fe","name":"util-linux","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-53614","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53614","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53614","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3accc11c0ad101fe","name":"util-linux","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.5","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:13","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3accc11c0ad101fe","name":"util-linux","version":"2.41-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.5","upstreams":[]}}],"ignoredMatches":[{"vulnerability":{"id":"CVE-2011-3389","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3389","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.","cvss":[],"epss":[{"cve":"CVE-2011-3389","epss":0.73327,"percentile":0.99401,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.66635},"relatedVulnerabilities":[{"id":"CVE-2011-3389","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3389","namespace":"nvd:cpe","severity":"Medium","urls":["http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/","http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx","http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx","http://curl.haxx.se/docs/adv_20120124B.html","http://downloads.asterisk.org/pub/security/AST-2016-001.html","http://ekoparty.org/2011/juliano-rizzo.php","http://eprint.iacr.org/2004/111","http://eprint.iacr.org/2006/136","http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html","http://isc.sans.edu/diary/SSL+TLS+part+3+/11635","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html","http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html","http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html","http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://marc.info/?l=bugtraq&m=132750579901589&w=2","http://marc.info/?l=bugtraq&m=132872385320240&w=2","http://marc.info/?l=bugtraq&m=133365109612558&w=2","http://marc.info/?l=bugtraq&m=133728004526190&w=2","http://marc.info/?l=bugtraq&m=134254866602253&w=2","http://marc.info/?l=bugtraq&m=134254957702612&w=2","http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue","http://osvdb.org/74829","http://rhn.redhat.com/errata/RHSA-2012-0508.html","http://rhn.redhat.com/errata/RHSA-2013-1455.html","http://secunia.com/advisories/45791","http://secunia.com/advisories/47998","http://secunia.com/advisories/48256","http://secunia.com/advisories/48692","http://secunia.com/advisories/48915","http://secunia.com/advisories/48948","http://secunia.com/advisories/49198","http://secunia.com/advisories/55322","http://secunia.com/advisories/55350","http://secunia.com/advisories/55351","http://security.gentoo.org/glsa/glsa-201203-02.xml","http://security.gentoo.org/glsa/glsa-201406-32.xml","http://support.apple.com/kb/HT4999","http://support.apple.com/kb/HT5001","http://support.apple.com/kb/HT5130","http://support.apple.com/kb/HT5281","http://support.apple.com/kb/HT5501","http://support.apple.com/kb/HT6150","http://technet.microsoft.com/security/advisory/2588513","http://vnhacker.blogspot.com/2011/09/beast.html","http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf","http://www.debian.org/security/2012/dsa-2398","http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html","http://www.ibm.com/developerworks/java/jdk/alerts/","http://www.imperialviolet.org/2011/09/23/chromeandbeast.html","http://www.insecure.cl/Beast-SSL.rar","http://www.kb.cert.org/vuls/id/864643","http://www.mandriva.com/security/advisories?name=MDVSA-2012:058","http://www.opera.com/docs/changelogs/mac/1151/","http://www.opera.com/docs/changelogs/mac/1160/","http://www.opera.com/docs/changelogs/unix/1151/","http://www.opera.com/docs/changelogs/unix/1160/","http://www.opera.com/docs/changelogs/windows/1151/","http://www.opera.com/docs/changelogs/windows/1160/","http://www.opera.com/support/kb/view/1004/","http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html","http://www.redhat.com/support/errata/RHSA-2011-1384.html","http://www.redhat.com/support/errata/RHSA-2012-0006.html","http://www.securityfocus.com/bid/49388","http://www.securityfocus.com/bid/49778","http://www.securitytracker.com/id/1029190","http://www.securitytracker.com/id?1025997","http://www.securitytracker.com/id?1026103","http://www.securitytracker.com/id?1026704","http://www.ubuntu.com/usn/USN-1263-1","http://www.us-cert.gov/cas/techalerts/TA12-010A.html","https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail","https://bugzilla.novell.com/show_bug.cgi?id=719047","https://bugzilla.redhat.com/show_bug.cgi?id=737506","https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006","https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862","https://hermes.opensuse.org/messages/13154861","https://hermes.opensuse.org/messages/13155432","https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"],"description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-3389","epss":0.73327,"percentile":0.99401,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u4"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2011-3389","versionConstraint":"none (unknown)"}}],"artifact":{"id":"8eb49376d7dae4e0","name":"libgnutls30t64","version":"3.8.9-3+deb13u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u4?arch=amd64&distro=debian-13.5&upstream=gnutls28","upstreams":[{"name":"gnutls28"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"libgnutls30t64","language":""}}]},{"vulnerability":{"id":"CVE-2011-4116","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4116","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks.","cvss":[],"epss":[{"cve":"CVE-2011-4116","epss":0.0052,"percentile":0.40722,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.026},"relatedVulnerabilities":[{"id":"CVE-2011-4116","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4116","namespace":"nvd:cpe","severity":"Low","urls":["http://www.openwall.com/lists/oss-security/2011/11/04/2","http://www.openwall.com/lists/oss-security/2011/11/04/4","https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14","https://rt.cpan.org/Public/Bug/Display.html?id=69106","https://seclists.org/oss-sec/2011/q4/238"],"description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:S/C:N/I:P/A:N","metrics":{"baseScore":1.5,"exploitabilityScore":2.7,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-4116","epss":0.0052,"percentile":0.40722,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2011-4116","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2021-45346","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-45346","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.","cvss":[],"epss":[{"cve":"CVE-2021-45346","epss":0.01614,"percentile":0.73302,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2021-45346","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08070000000000001},"relatedVulnerabilities":[{"id":"CVE-2021-45346","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-45346","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/guyinatuxedo/sqlite3_record_leaking","https://security.netapp.com/advisory/ntap-20220303-0001/","https://sqlite.org/forum/forumpost/056d557c2f8c452ed5","https://sqlite.org/forum/forumpost/53de8864ba114bf6","https://www.sqlite.org/cves.html#status_of_recent_sqlite_cves"],"description":"A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","metrics":{"baseScore":4,"exploitabilityScore":8,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-45346","epss":0.01614,"percentile":0.73302,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2021-45346","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2021-45346","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fdc2417d59a35191","name":"libsqlite3-0","version":"3.46.1-7+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"libsqlite3-0","language":""}}]},{"vulnerability":{"id":"CVE-2025-15649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15649","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15649","epss":0.00127,"percentile":0.02733,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2025-15649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15649","epss":0.00127,"percentile":0.02733,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05043999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d73c99dbc97f6ec0","name":"dirmngr","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/dirmngr@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2025-68972","namespace":""}]},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05043999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ced4de0e43890bd3","name":"gnupg","version":"2.4.7-21+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gnupg:gnupg:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg@2.4.7-21%2Bdeb13u1?arch=all&distro=debian-13.5&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2025-68972","namespace":""}]},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05043999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"deb1d413d83f82b8","name":"gnupg-l10n","version":"2.4.7-21+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-l10n@2.4.7-21%2Bdeb13u1?arch=all&distro=debian-13.5&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2025-68972","namespace":""}]},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05043999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cd76d9c17a1cf27f","name":"gpg","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.list"},{"path":"/var/lib/dpkg/info/gpg.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.postinst"},{"path":"/var/lib/dpkg/info/gpg.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg.postrm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpg:gpg:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2025-68972","namespace":""}]},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05043999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2660f16d4b2ce1d7","name":"gpg-agent","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-agent@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2025-68972","namespace":""}]},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05043999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c44d319fa06436ce","name":"gpgconf","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgconf@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2025-68972","namespace":""}]},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05043999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00104,"percentile":0.01204,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"321974a38b0687e6","name":"gpgsm","version":"2.4.7-21+deb13u1+b3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.7-21\\+deb13u1\\+b3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgsm@2.4.7-21%2Bdeb13u1%2Bb3?arch=amd64&distro=debian-13.5&upstream=gnupg2%402.4.7-21%2Bdeb13u1","upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2025-68972","namespace":""}]},{"vulnerability":{"id":"CVE-2025-70873","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-70873","namespace":"debian:distro:debian:13","severity":"Negligible","urls":[],"description":"An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.","cvss":[],"epss":[{"cve":"CVE-2025-70873","epss":0.00301,"percentile":0.22029,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-70873","cwe":"CWE-244","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.015050000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-70873","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-70873","namespace":"nvd:cpe","severity":"High","urls":["https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054","https://sqlite.org/forum/forumpost/761eac3c82","https://sqlite.org/src/info/3d459f1fb1bd1b5e"],"description":"An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-70873","epss":0.00301,"percentile":0.22029,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2025-70873","cwe":"CWE-244","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2025-70873","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fdc2417d59a35191","name":"libsqlite3-0","version":"3.46.1-7+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"libsqlite3-0","language":""}}]},{"vulnerability":{"id":"CVE-2026-11822","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11822","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11822","epss":0.00175,"percentile":0.07214,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.14},"relatedVulnerabilities":[{"id":"CVE-2026-11822","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11822","namespace":"nvd:cpe","severity":"High","urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"],"description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11822","epss":0.00175,"percentile":0.07214,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11822","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fdc2417d59a35191","name":"libsqlite3-0","version":"3.46.1-7+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"libsqlite3-0","language":""}}]},{"vulnerability":{"id":"CVE-2026-11824","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11824","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11824","epss":0.00175,"percentile":0.07214,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.14},"relatedVulnerabilities":[{"id":"CVE-2026-11824","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11824","namespace":"nvd:cpe","severity":"High","urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-heap-buffer-overflow-via-fts5-fts5chunkiterate"],"description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11824","epss":0.00175,"percentile":0.07214,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-11824","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fdc2417d59a35191","name":"libsqlite3-0","version":"3.46.1-7+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"libsqlite3-0","language":""}}]},{"vulnerability":{"id":"CVE-2026-12087","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12087","epss":0.00389,"percentile":0.31197,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-12087","cwe":"CWE-805","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.352045},"relatedVulnerabilities":[{"id":"CVE-2026-12087","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12087","epss":0.00389,"percentile":0.31197,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-12087","cwe":"CWE-805","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-13221","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13221","epss":0.00606,"percentile":0.4503,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.54843},"relatedVulnerabilities":[{"id":"CVE-2026-13221","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"description":"Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13221","epss":0.00606,"percentile":0.4503,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-42496","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42496","epss":0.0043,"percentile":0.3486,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42496","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.38915},"relatedVulnerabilities":[{"id":"CVE-2026-42496","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42496","epss":0.0043,"percentile":0.3486,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42496","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-42497","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42497","epss":0.00417,"percentile":0.33824,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42497","cwe":"CWE-732","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.31275000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-42497","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42497","epss":0.00417,"percentile":0.33824,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42497","cwe":"CWE-732","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-48959","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48959","epss":0.00373,"percentile":0.29614,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27974999999999994},"relatedVulnerabilities":[{"id":"CVE-2026-48959","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48959","epss":0.00373,"percentile":0.29614,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-48961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48961","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48961","epss":0.00262,"percentile":0.17695,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19388},"relatedVulnerabilities":[{"id":"CVE-2026-48961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48961","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/3"],"description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48961","epss":0.00262,"percentile":0.17695,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-48961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-48962","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48962","epss":0.00292,"percentile":0.21102,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-48962","cwe":"CWE-94","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22337999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-48962","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48962","epss":0.00292,"percentile":0.21102,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-48962","cwe":"CWE-94","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-50812","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50812","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50812","epss":0.00112,"percentile":0.01649,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0588},"relatedVulnerabilities":[{"id":"CVE-2026-50812","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50812","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/junius-sec/bb556f333957c5226dede314db0e9e91","https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d","https://sqlite.org/src/info/e807d4e3798efd53"],"description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50812","epss":0.00112,"percentile":0.01649,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-50812","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fdc2417d59a35191","name":"libsqlite3-0","version":"3.46.1-7+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"libsqlite3-0","language":""}}]},{"vulnerability":{"id":"CVE-2026-50813","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50813","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50813","epss":0.00111,"percentile":0.01592,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-50813","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05827500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-50813","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50813","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/junius-sec/f8acb66bafb80134c8e1a1c8c7c9f4f4","https://github.com/sqlite/sqlite/commit/c597ed79d1bd03f57198d10d1f431adda293cf2e","https://sqlite.org/src/info/869a51ae84df"],"description":"An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50813","epss":0.00111,"percentile":0.01592,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-50813","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u1"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-50813","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fdc2417d59a35191","name":"libsqlite3-0","version":"3.46.1-7+deb13u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64&distro=debian-13.5&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"libsqlite3-0","language":""}}]},{"vulnerability":{"id":"CVE-2026-5450","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.39643,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47188},"relatedVulnerabilities":[{"id":"CVE-2026-5450","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","namespace":"nvd:cpe","severity":"Critical","urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.39643,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1ded7e36f657ba6e","name":"libc-bin","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2026-5450","namespace":""}]},{"vulnerability":{"id":"CVE-2026-5450","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.39643,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47188},"relatedVulnerabilities":[{"id":"CVE-2026-5450","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","namespace":"nvd:cpe","severity":"Critical","urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.39643,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1e14850bd315eb8f","name":"libc6","version":"2.41-12+deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.5&upstream=glibc","upstreams":[{"name":"glibc"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2026-5450","namespace":""}]},{"vulnerability":{"id":"CVE-2026-57432","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57432","epss":0.00196,"percentile":0.0954,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-57432","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15582000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-57432","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"description":"Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57432","epss":0.00196,"percentile":0.0954,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-57432","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-57433","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57433","epss":0.00345,"percentile":0.26721,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.32430000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-57433","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57433","epss":0.00345,"percentile":0.26721,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-58016","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58016","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58016","epss":0.00373,"percentile":0.29596,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.337565},"relatedVulnerabilities":[{"id":"CVE-2026-58016","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016","namespace":"nvd:cpe","severity":"Critical","urls":["https://access.redhat.com/security/cve/CVE-2026-58016","https://bugzilla.redhat.com/show_bug.cgi?id=2492257","https://gitlab.gnome.org/GNOME/glib/-/issues/3932"],"description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58016","epss":0.00373,"percentile":0.29596,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"glib2.0","version":"2.84.4-3~deb13u3"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-58016","versionConstraint":"none (unknown)"}}],"artifact":{"id":"40a29caaab142509","name":"libglib2.0-0t64","version":"2.84.4-3~deb13u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libglib2.0-0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0t64:2.84.4-3\\~deb13u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0t64@2.84.4-3~deb13u3?arch=amd64&distro=debian-13.5&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2026-58016","namespace":""}]},{"vulnerability":{"id":"CVE-2026-7010","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","namespace":"debian:distro:debian:13","severity":"Medium","urls":[],"description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7010","epss":0.00227,"percentile":0.13348,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13052499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-7010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7010","epss":0.00227,"percentile":0.13348,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-7017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7017","epss":0.0026,"percentile":0.17565,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1898},"relatedVulnerabilities":[{"id":"CVE-2026-7017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7017","epss":0.0026,"percentile":0.17565,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.0079,"percentile":0.52166,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5925},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.0079,"percentile":0.52166,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bffe16eb203857d1","name":"libpython3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13:libpython3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2026-7210","namespace":""}]},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.0079,"percentile":0.52166,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5925},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.0079,"percentile":0.52166,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5416ba7a6d375000","name":"libpython3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2026-7210","namespace":""}]},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.0079,"percentile":0.52166,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5925},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.0079,"percentile":0.52166,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e27ee79cf76c6af","name":"libpython3.13-stdlib","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":[],"cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2026-7210","namespace":""}]},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.0079,"percentile":0.52166,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5925},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.0079,"percentile":0.52166,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80a22b0bca4d7047","name":"python3.13","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5","upstreams":[]},"appliedIgnoreRules":[{"vulnerability":"CVE-2026-7210","namespace":""}]},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.0079,"percentile":0.52166,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5925},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.0079,"percentile":0.52166,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u2"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6255be8608fd4dff","name":"python3.13-minimal","version":"3.13.5-2+deb13u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u2?arch=amd64&distro=debian-13.5&upstream=python3.13","upstreams":[{"name":"python3.13"}]},"appliedIgnoreRules":[{"vulnerability":"CVE-2026-7210","namespace":""}]},{"vulnerability":{"id":"CVE-2026-8376","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","namespace":"debian:distro:debian:13","severity":"Critical","urls":[],"description":"Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8376","epss":0.00398,"percentile":0.32117,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.37412},"relatedVulnerabilities":[{"id":"CVE-2026-8376","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"description":"Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8376","epss":0.00398,"percentile":0.32117,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]},{"vulnerability":{"id":"CVE-2026-9538","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","namespace":"debian:distro:debian:13","severity":"High","urls":[],"description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9538","epss":0.00437,"percentile":0.35389,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.32775},"relatedVulnerabilities":[{"id":"CVE-2026-9538","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9538","epss":0.00437,"percentile":0.35389,"date":"2026-07-18"}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.5"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"},"found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9529c7e8aff3730f","name":"perl-base","version":"5.40.1-6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"language":"","licenses":[],"cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.5&upstream=perl","upstreams":[{"name":"perl"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"perl-base","language":""}}]}],"source":{"type":"image","target":{"userInput":"ghcr.io/freedomofpress/dangerzone/v1:latest","imageID":"sha256:9f3234b9c53e62038bc7d0daf374a283b2aa279ea58771552ce0204abb0a47d6","manifestDigest":"sha256:fa142f3dd72f7eca82bf372fd407d8f2d20f8593237411727bb1cc0e65015106","mediaType":"application/vnd.docker.distribution.manifest.v2+json","tags":["ghcr.io/freedomofpress/dangerzone/v1:latest"],"imageSize":1066338482,"layers":[{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:b0e76aa57564044d18e26e6a50d43576996529352eba9e2fbb7ab449ebac9aa2","size":1066338482}],"manifest":"eyJzY2hlbWFWZXJzaW9uIjoyLCJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmRpc3RyaWJ1dGlvbi5tYW5pZmVzdC52Mitqc29uIiwiY29uZmlnIjp7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuY29udGFpbmVyLmltYWdlLnYxK2pzb24iLCJzaXplIjo3MjIsImRpZ2VzdCI6InNoYTI1Njo5ZjMyMzRiOWM1M2U2MjAzOGJjN2QwZGFmMzc0YTI4M2IyYWEyNzllYTU4NzcxNTUyY2UwMjA0YWJiMGE0N2Q2In0sImxheWVycyI6W3sibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjEwNzQwODA3NjgsImRpZ2VzdCI6InNoYTI1NjpiMGU3NmFhNTc1NjQwNDRkMThlMjZlNmE1MGQ0MzU3Njk5NjUyOTM1MmViYTllMmZiYjdhYjQ0OWViYWM5YWEyIn1dfQ==","config":"eyJhcmNoaXRlY3R1cmUiOiJhbWQ2NCIsImNvbmZpZyI6eyJVc2VyIjoiZGFuZ2Vyem9uZSIsIkVudiI6WyJQQVRIPS91c3IvbG9jYWwvc2JpbjovdXNyL2xvY2FsL2JpbjovdXNyL3NiaW46L3Vzci9iaW46L3NiaW46L2JpbiJdLCJFbnRyeXBvaW50IjpbIi9lbnRyeXBvaW50LnB5Il0sIldvcmtpbmdEaXIiOiIvIn0sImNyZWF0ZWQiOiIyMDI2LTA2LTMwVDAwOjAwOjAwWiIsImhpc3RvcnkiOlt7ImNyZWF0ZWQiOiIyMDI2LTA2LTMwVDAwOjAwOjAwWiIsImNyZWF0ZWRfYnkiOiJDT1BZIC9uZXdfcm9vdC8gLyAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA2LTMwVDAwOjAwOjAwWiIsImNyZWF0ZWRfYnkiOiJVU0VSIGRhbmdlcnpvbmUiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA2LTMwVDAwOjAwOjAwWiIsImNyZWF0ZWRfYnkiOiJFTlRSWVBPSU5UIFtcIi9lbnRyeXBvaW50LnB5XCJdIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX1dLCJvcyI6ImxpbnV4Iiwicm9vdGZzIjp7InR5cGUiOiJsYXllcnMiLCJkaWZmX2lkcyI6WyJzaGEyNTY6YjBlNzZhYTU3NTY0MDQ0ZDE4ZTI2ZTZhNTBkNDM1NzY5OTY1MjkzNTJlYmE5ZTJmYmI3YWI0NDllYmFjOWFhMiJdfX0=","repoDigests":["ghcr.io/freedomofpress/dangerzone/v1@sha256:527da9012343066523c5561af64328dd13f79bf74b6c612d31fa8563b2e8ae2a"],"architecture":"amd64","os":"linux"}},"distro":{"name":"debian","version":"13.5","idLike":[]},"descriptor":{"name":"grype","version":"0.116.0","configuration":{"output":["json"],"file":"report.json","pretty":false,"distro":"","add-cpes-if-none":false,"output-template-file":"","check-for-app-update":true,"only-fixed":false,"only-notfixed":false,"ignore-wontfix":"","platform":"","search":{"scope":"squashed","unindexed-archives":false,"indexed-archives":true},"ignore":[{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"libsqlite3-0","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"gnutls28","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"libgnutls30t64","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"libssh2-1t64","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"perl-base","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2023-45853","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2024-38428","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2024-57823","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2025-0665","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2025-43859","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"GHSA-vqfr-h8mv-ghfj","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2025-2866","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2025-4802","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2025-4517","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2025-49794","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2025-49796","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2025-13836","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2025-68973","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2025-68972","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2026-6100","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"GHSA-pg25-7cx5-cvcm","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2026-5450","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2026-7210","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"CVE-2026-58016","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"","version":"","language":"","type":"","location":"","upstream-name":""},"vex-status":"","vex-justification":"","match-type":""},{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"kernel-headers","version":"","language":"","type":"rpm","location":"","upstream-name":"kernel"},"vex-status":"","vex-justification":"","match-type":"exact-indirect-match"},{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"linux(-.*)?-headers-.*","version":"","language":"","type":"deb","location":"","upstream-name":"linux.*"},"vex-status":"","vex-justification":"","match-type":"exact-indirect-match"},{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"linux-libc-dev","version":"","language":"","type":"deb","location":"","upstream-name":"linux"},"vex-status":"","vex-justification":"","match-type":"exact-indirect-match"},{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"linux-kbuild-.*","version":"","language":"","type":"deb","location":"","upstream-name":"linux.*"},"vex-status":"","vex-justification":"","match-type":"exact-indirect-match"}],"exclude":[],"externalSources":{"enable":false,"maven":{"searchUpstreamBySha1":true,"baseUrl":"https://search.maven.org/solrsearch/select","rateLimit":300000000}},"match":{"java":{"using-cpes":false},"jvm":{"using-cpes":true},"dotnet":{"using-cpes":false},"golang":{"using-cpes":false,"always-use-cpe-for-stdlib":false,"allow-main-module-pseudo-version-comparison":false},"javascript":{"using-cpes":false},"python":{"using-cpes":false},"ruby":{"using-cpes":false},"rust":{"using-cpes":false},"hex":{"using-cpes":false},"stock":{"using-cpes":true},"dpkg":{"using-cpes":false,"missing-epoch-strategy":"zero","use-cpes-for-eol":false},"rpm":{"using-cpes":false,"missing-epoch-strategy":"auto","use-cpes-for-eol":false}},"fail-on-severity":"","registry":{"insecure-skip-tls-verify":false,"insecure-use-http":false,"ca-cert":""},"show-suppressed":false,"by-cve":false,"SortBy":{"sort-by":"risk"},"name":"","default-image-pull-source":"","from":null,"vex-documents":[],"vex-add":[],"match-upstream-kernel-headers":false,"fix-channel":{"redhat-eus":{"apply":"auto","versions":">= 8.0"},"ubuntu-esm":{"apply":"auto","versions":""}},"timestamp":true,"alerts":{"enable-eol-distro-warnings":true},"db":{"cache-dir":"/home/runner/.cache/grype/db","update-url":"https://grype.anchore.io/databases","ca-cert":"","auto-update":true,"validate-by-hash-on-start":true,"validate-age":true,"max-allowed-built-age":432000000000000,"require-update-check":false,"update-available-timeout":30000000000,"update-download-timeout":300000000000,"max-update-check-frequency":7200000000000},"exp":{},"dev":{"db":{"debug":false}}},"db":{"status":{"schemaVersion":"v6.1.9","from":"https://grype.anchore.io/databases/v6/vulnerability-db_v6.1.9_2026-07-19T00:37:02Z_1784444456.tar.zst?checksum=sha256%3Ad0b377f7c0e72a3ccc1f3418d91877154229df26720e284cefd74d27633f96ea","built":"2026-07-19T07:00:56Z","path":"/home/runner/.cache/grype/db/6/vulnerability.db","valid":true},"providers":{"alma":{"captured":"2026-07-19T00:37:36Z","input":"xxh64:242add25c7cbc607"},"alpine":{"captured":"2026-07-19T00:37:05Z","input":"xxh64:0cd11fcb29053637"},"amazon":{"captured":"2026-07-19T00:37:04Z","input":"xxh64:2d11d4f41acc1f91"},"arch":{"captured":"2026-07-19T00:37:09Z","input":"xxh64:bbada5b096490f25"},"bitnami":{"captured":"2026-07-19T00:37:05Z","input":"xxh64:ee21dfef0fd58beb"},"chainguard":{"captured":"2026-07-19T00:37:27Z","input":"xxh64:e8e65469ed10f280"},"chainguard-libraries":{"captured":"2026-07-19T00:37:02Z","input":"xxh64:a0aadf83585be126"},"debian":{"captured":"2026-07-19T00:37:28Z","input":"xxh64:205e37b545428cc6"},"echo":{"captured":"2026-07-19T00:37:31Z","input":"xxh64:a3de65c1a7dc5dca"},"eol":{"captured":"2026-07-19T00:37:34Z","input":"xxh64:59d2f7abea5cafd1"},"epss":{"captured":"2026-07-19T00:37:35Z","input":"xxh64:3b93ed3de77efe52"},"fedora":{"captured":"2026-07-19T00:37:11Z","input":"xxh64:99e236f1db51d290"},"github":{"captured":"2026-07-19T00:37:14Z","input":"xxh64:ccbfae1fccf96351"},"govulndb":{"captured":"2026-07-19T00:37:38Z","input":"xxh64:6a55f282197e3119"},"hummingbird":{"captured":"2026-07-19T00:39:20Z","input":"xxh64:60b8e1d45e5aefe4"},"kev":{"captured":"2026-07-19T00:37:07Z","input":"xxh64:0e2bf04647ece134"},"mariner":{"captured":"2026-07-19T00:37:04Z","input":"xxh64:49bbf47456183dda"},"minimos":{"captured":"2026-07-19T00:37:10Z","input":"xxh64:b9b8edfdd82f29cf"},"nvd":{"captured":"2026-07-19T00:38:29Z","input":"xxh64:e9fbf57521bdf214"},"oracle":{"captured":"2026-07-19T00:37:16Z","input":"xxh64:d2a6a963cee52d36"},"photon":{"captured":"2026-07-19T00:37:07Z","input":"xxh64:13fbebd8c735c7f3"},"rhel":{"captured":"2026-07-19T00:38:35Z","input":"xxh64:7ac4a9c743ae114a"},"secureos":{"captured":"2026-07-19T00:37:34Z","input":"xxh64:86be78dd84bc5ec0"},"sles":{"captured":"2026-07-19T00:38:04Z","input":"xxh64:df634e5b4db7b44a"},"ubuntu":{"captured":"2026-07-19T00:38:37Z","input":"xxh64:1b61620bf790cc84"},"wolfi":{"captured":"2026-07-19T00:37:03Z","input":"xxh64:5afdb41e2a351cc0"}}},"timestamp":"2026-07-20T03:07:14.948365331Z"}}
