{
  "matches": [
    {
      "vulnerability": {
        "id": "CVE-2024-7264",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-7264",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libcurl, where libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If a syntactically incorrect field is given, the parser can use -1 for the length of the *time fraction*, leading to a `strlen()` performed on a pointer to a heap buffer area that is not purposely NULL terminated.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.1,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-7264",
            "epss": 0.17301,
            "percentile": 0.96791,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-7264",
            "cwe": "CWE-125",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 7.179915
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-7264",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-7264",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "http://www.openwall.com/lists/oss-security/2024/07/31/1",
            "https://curl.se/docs/CVE-2024-7264.html",
            "https://curl.se/docs/CVE-2024-7264.json",
            "https://hackerone.com/reports/2629968",
            "https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519",
            "https://security.netapp.com/advisory/ntap-20240828-0008/",
            "https://security.netapp.com/advisory/ntap-20241025-0006/",
            "https://security.netapp.com/advisory/ntap-20241025-0010/"
          ],
          "description": "libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 6.3,
                "exploitabilityScore": 2.9,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-7264",
              "epss": 0.17301,
              "percentile": 0.96791,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-7264",
              "cwe": "CWE-125",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-7264",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-7264",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-7264",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libcurl, where libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If a syntactically incorrect field is given, the parser can use -1 for the length of the *time fraction*, leading to a `strlen()` performed on a pointer to a heap buffer area that is not purposely NULL terminated.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.1,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-7264",
            "epss": 0.17301,
            "percentile": 0.96791,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-7264",
            "cwe": "CWE-125",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 7.179915
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-7264",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-7264",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "http://www.openwall.com/lists/oss-security/2024/07/31/1",
            "https://curl.se/docs/CVE-2024-7264.html",
            "https://curl.se/docs/CVE-2024-7264.json",
            "https://hackerone.com/reports/2629968",
            "https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519",
            "https://security.netapp.com/advisory/ntap-20240828-0008/",
            "https://security.netapp.com/advisory/ntap-20241025-0006/",
            "https://security.netapp.com/advisory/ntap-20241025-0010/"
          ],
          "description": "libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 6.3,
                "exploitabilityScore": 2.9,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-7264",
              "epss": 0.17301,
              "percentile": 0.96791,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-7264",
              "cwe": "CWE-125",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-7264",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-45447",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-45447",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in OpenSSL. When processing a specially crafted PKCS#7 or S/MIME (Secure/Multipurpose Internet Mail Extensions) signed message, a heap use-after-free vulnerability in the PKCS7_verify() function can be triggered. This occurs if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, leading to incorrect memory deallocation. A remote attacker could exploit this to cause application crashes, memory corruption, or potentially achieve remote code execution.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.3,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-45447",
            "epss": 0.05236,
            "percentile": 0.91668,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-45447",
            "cwe": "CWE-416",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-45447",
            "cwe": "CWE-825",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 4.084079999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-45447",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-45447",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c",
            "https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8",
            "https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54",
            "https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c",
            "https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e",
            "https://openssl-library.org/news/secadv/20260609.txt",
            "https://access.redhat.com/errata/RHSA-2026:25237",
            "https://access.redhat.com/errata/RHSA-2026:25239",
            "https://access.redhat.com/errata/RHSA-2026:26275",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:34102",
            "https://access.redhat.com/errata/RHSA-2026:35869",
            "https://access.redhat.com/errata/RHSA-2026:36215",
            "https://access.redhat.com/errata/RHSA-2026:36217",
            "https://access.redhat.com/errata/RHSA-2026:39009",
            "https://access.redhat.com/errata/RHSA-2026:39012",
            "https://access.redhat.com/errata/RHSA-2026:39981",
            "https://access.redhat.com/errata/RHSA-2026:44438",
            "https://access.redhat.com/security/cve/CVE-2026-45447",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2481898",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"
          ],
          "description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.3,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-45447",
              "epss": 0.05236,
              "percentile": 0.91668,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-45447",
              "cwe": "CWE-416",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-45447",
              "cwe": "CWE-825",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-45447",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-45447",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-45447",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in OpenSSL. When processing a specially crafted PKCS#7 or S/MIME (Secure/Multipurpose Internet Mail Extensions) signed message, a heap use-after-free vulnerability in the PKCS7_verify() function can be triggered. This occurs if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, leading to incorrect memory deallocation. A remote attacker could exploit this to cause application crashes, memory corruption, or potentially achieve remote code execution.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.3,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-45447",
            "epss": 0.05236,
            "percentile": 0.91668,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-45447",
            "cwe": "CWE-416",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-45447",
            "cwe": "CWE-825",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 4.084079999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-45447",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-45447",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c",
            "https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8",
            "https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54",
            "https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c",
            "https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e",
            "https://openssl-library.org/news/secadv/20260609.txt",
            "https://access.redhat.com/errata/RHSA-2026:25237",
            "https://access.redhat.com/errata/RHSA-2026:25239",
            "https://access.redhat.com/errata/RHSA-2026:26275",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:34102",
            "https://access.redhat.com/errata/RHSA-2026:35869",
            "https://access.redhat.com/errata/RHSA-2026:36215",
            "https://access.redhat.com/errata/RHSA-2026:36217",
            "https://access.redhat.com/errata/RHSA-2026:39009",
            "https://access.redhat.com/errata/RHSA-2026:39012",
            "https://access.redhat.com/errata/RHSA-2026:39981",
            "https://access.redhat.com/errata/RHSA-2026:44438",
            "https://access.redhat.com/security/cve/CVE-2026-45447",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2481898",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"
          ],
          "description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.3,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-45447",
              "epss": 0.05236,
              "percentile": 0.91668,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-45447",
              "cwe": "CWE-416",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-45447",
              "cwe": "CWE-825",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-45447",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42009",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42009",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42009",
            "epss": 0.01335,
            "percentile": 0.68258,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42009",
            "cwe": "CWE-475",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-42009",
            "cwe": "CWE-475",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 1.00125
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42009",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42009",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:29794",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:34372",
            "https://access.redhat.com/errata/RHSA-2026:34764",
            "https://access.redhat.com/errata/RHSA-2026:34788",
            "https://access.redhat.com/errata/RHSA-2026:36004",
            "https://access.redhat.com/errata/RHSA-2026:36005",
            "https://access.redhat.com/errata/RHSA-2026:36006",
            "https://access.redhat.com/errata/RHSA-2026:40762",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/security/cve/CVE-2026-42009",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467279",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json"
          ],
          "description": "A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42009",
              "epss": 0.01335,
              "percentile": 0.68258,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42009",
              "cwe": "CWE-475",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-42009",
              "cwe": "CWE-475",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42009",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-34459",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-34459",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in the xmllint program distributed by the libxml2 package. A buffer over-read in the xmlHTMLPrintFileContext function in the xmllint.c file may be triggered when a crafted file is processed with the xmllint program using the `--htmlout` command line option, causing an application crash and resulting in a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 1.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-34459",
            "epss": 0.02298,
            "percentile": 0.81507,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-34459",
            "cwe": "CWE-122",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.9.13-14.el9_8.1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.9.13-14.el9_8.1",
              "date": "2026-06-24",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:28254",
            "link": "https://access.redhat.com/errata/RHSA-2026:28254"
          }
        ],
        "risk": 0.9766500000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-34459",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-34459",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://gitlab.gnome.org/GNOME/libxml2/-/issues/720",
            "https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.11.8",
            "https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.12.7",
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5HVUXKYTBWT3G5DEEQX62STJQBY367NL/",
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/INKSSLW5VMZIXHRPZBAW4TJUX5SQKARG/",
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VRDJCNQP32LV56KESUQ5SNZKAJWSZZRI/",
            "https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html",
            "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5HVUXKYTBWT3G5DEEQX62STJQBY367NL/",
            "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/INKSSLW5VMZIXHRPZBAW4TJUX5SQKARG/",
            "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VRDJCNQP32LV56KESUQ5SNZKAJWSZZRI/"
          ],
          "description": "An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-34459",
              "epss": 0.02298,
              "percentile": 0.81507,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-34459",
              "cwe": "CWE-122",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libxml2",
              "version": "0:2.9.13-14.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-34459",
            "versionConstraint": "< 0:2.9.13-14.el9_8.1 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.9.13-14.el9_8.1"
          }
        }
      ],
      "artifact": {
        "id": "a840257087cebda4",
        "name": "libxml2",
        "version": "2.9.13-14.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libxml2-2.9.13-14.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-33846",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-33846",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-33846",
            "epss": 0.01263,
            "percentile": 0.66672,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-33846",
            "cwe": "CWE-130",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-33846",
            "cwe": "CWE-130",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.94725
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-33846",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-33846",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:34372",
            "https://access.redhat.com/errata/RHSA-2026:36004",
            "https://access.redhat.com/errata/RHSA-2026:36005",
            "https://access.redhat.com/errata/RHSA-2026:36006",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/security/cve/CVE-2026-33846",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2450625",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33846.json"
          ],
          "description": "A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-33846",
              "epss": 0.01263,
              "percentile": 0.66672,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-33846",
              "cwe": "CWE-130",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-33846",
              "cwe": "CWE-130",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-33846",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42010",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42010",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
            "metrics": {
              "baseScore": 7.1,
              "exploitabilityScore": 2.9,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42010",
            "epss": 0.0105,
            "percentile": 0.60781,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42010",
            "cwe": "CWE-170",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-42010",
            "cwe": "CWE-626",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-42010",
            "cwe": "CWE-170",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.7665
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42010",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42010",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:34764",
            "https://access.redhat.com/errata/RHSA-2026:34788",
            "https://access.redhat.com/errata/RHSA-2026:34790",
            "https://access.redhat.com/errata/RHSA-2026:36004",
            "https://access.redhat.com/errata/RHSA-2026:36005",
            "https://access.redhat.com/errata/RHSA-2026:36006",
            "https://access.redhat.com/errata/RHSA-2026:40762",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/security/cve/CVE-2026-42010",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467289",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-4",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42010.json"
          ],
          "description": "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 2.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 2.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42010",
              "epss": 0.0105,
              "percentile": 0.60781,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42010",
              "cwe": "CWE-170",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-42010",
              "cwe": "CWE-626",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-42010",
              "cwe": "CWE-170",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42010",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-9681",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-9681",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A vulnerability was found in curl. When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than intended.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 3.9,
              "exploitabilityScore": 1.4,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-9681",
            "epss": 0.0203,
            "percentile": 0.79041,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-9681",
            "cwe": "CWE-697",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.7003499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-9681",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-9681",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2024-9681.html",
            "https://curl.se/docs/CVE-2024-9681.json",
            "https://hackerone.com/reports/2764830",
            "http://seclists.org/fulldisclosure/2025/Apr/10",
            "http://seclists.org/fulldisclosure/2025/Apr/11",
            "http://seclists.org/fulldisclosure/2025/Apr/12",
            "http://seclists.org/fulldisclosure/2025/Apr/13",
            "http://seclists.org/fulldisclosure/2025/Apr/4",
            "http://seclists.org/fulldisclosure/2025/Apr/5",
            "http://seclists.org/fulldisclosure/2025/Apr/8",
            "http://seclists.org/fulldisclosure/2025/Apr/9",
            "http://www.openwall.com/lists/oss-security/2024/11/06/2",
            "https://security.netapp.com/advisory/ntap-20241213-0006/",
            "https://github.com/curl/curl/commit/7385610d0c74c6a25",
            "https://github.com/curl/curl/commit/a94973805df96269bf"
          ],
          "description": "When curl is asked to use HSTS, the expiry time for a subdomain might\noverwrite a parent domain's cache entry, making it end sooner or later than\notherwise intended.\n\nThis affects curl using applications that enable HSTS and use URLs with the\ninsecure `HTTP://` scheme and perform transfers with hosts like\n`x.example.com` as well as `example.com` where the first host is a subdomain\nof the second host.\n\n(The HSTS cache either needs to have been populated manually or there needs to\nhave been previous HTTPS accesses done as the cache needs to have entries for\nthe domains involved to trigger this problem.)\n\nWhen `x.example.com` responds with `Strict-Transport-Security:` headers, this\nbug can make the subdomain's expiry timeout *bleed over* and get set for the\nparent domain `example.com` in curl's HSTS cache.\n\nThe result of a triggered bug is that HTTP accesses to `example.com` get\nconverted to HTTPS for a different period of time than what was asked for by\nthe origin server. If `example.com` for example stops supporting HTTPS at its\nexpiry time, curl might then fail to access `http://example.com` until the\n(wrongly set) timeout expires. This bug can also expire the parent's entry\n*earlier*, thus making curl inadvertently switch back to insecure HTTP earlier\nthan otherwise intended.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.3,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-9681",
              "epss": 0.0203,
              "percentile": 0.79041,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-9681",
              "cwe": "CWE-697",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-9681",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-9681",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-9681",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A vulnerability was found in curl. When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than intended.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 3.9,
              "exploitabilityScore": 1.4,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-9681",
            "epss": 0.0203,
            "percentile": 0.79041,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-9681",
            "cwe": "CWE-697",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.7003499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-9681",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-9681",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2024-9681.html",
            "https://curl.se/docs/CVE-2024-9681.json",
            "https://hackerone.com/reports/2764830",
            "http://seclists.org/fulldisclosure/2025/Apr/10",
            "http://seclists.org/fulldisclosure/2025/Apr/11",
            "http://seclists.org/fulldisclosure/2025/Apr/12",
            "http://seclists.org/fulldisclosure/2025/Apr/13",
            "http://seclists.org/fulldisclosure/2025/Apr/4",
            "http://seclists.org/fulldisclosure/2025/Apr/5",
            "http://seclists.org/fulldisclosure/2025/Apr/8",
            "http://seclists.org/fulldisclosure/2025/Apr/9",
            "http://www.openwall.com/lists/oss-security/2024/11/06/2",
            "https://security.netapp.com/advisory/ntap-20241213-0006/",
            "https://github.com/curl/curl/commit/7385610d0c74c6a25",
            "https://github.com/curl/curl/commit/a94973805df96269bf"
          ],
          "description": "When curl is asked to use HSTS, the expiry time for a subdomain might\noverwrite a parent domain's cache entry, making it end sooner or later than\notherwise intended.\n\nThis affects curl using applications that enable HSTS and use URLs with the\ninsecure `HTTP://` scheme and perform transfers with hosts like\n`x.example.com` as well as `example.com` where the first host is a subdomain\nof the second host.\n\n(The HSTS cache either needs to have been populated manually or there needs to\nhave been previous HTTPS accesses done as the cache needs to have entries for\nthe domains involved to trigger this problem.)\n\nWhen `x.example.com` responds with `Strict-Transport-Security:` headers, this\nbug can make the subdomain's expiry timeout *bleed over* and get set for the\nparent domain `example.com` in curl's HSTS cache.\n\nThe result of a triggered bug is that HTTP accesses to `example.com` get\nconverted to HTTPS for a different period of time than what was asked for by\nthe origin server. If `example.com` for example stops supporting HTTPS at its\nexpiry time, curl might then fail to access `http://example.com` until the\n(wrongly set) timeout expires. This bug can also expire the parent's entry\n*earlier*, thus making curl inadvertently switch back to insecure HTTP earlier\nthan otherwise intended.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.3,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-9681",
              "epss": 0.0203,
              "percentile": 0.79041,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-9681",
              "cwe": "CWE-697",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-9681",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-9232",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-9232",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in the OpenSSL HTTP client API no_proxy handling. This vulnerability allows an application level denial of service (application crash) via an attacker-controlled IPv6 URL when the no_proxy environment variable is set.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.1,
              "exploitabilityScore": 1.7,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-9232",
            "epss": 0.02251,
            "percentile": 0.81098,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-9232",
            "cwe": "CWE-125",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.686555
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-9232",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-9232",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35",
            "https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b",
            "https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3",
            "https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf",
            "https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0",
            "https://openssl-library.org/news/secadv/20250930.txt",
            "http://www.openwall.com/lists/oss-security/2025/09/30/5",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-089022.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-485750.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
          ],
          "description": "Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-9232",
              "epss": 0.02251,
              "percentile": 0.81098,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-9232",
              "cwe": "CWE-125",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-9232",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-9232",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-9232",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in the OpenSSL HTTP client API no_proxy handling. This vulnerability allows an application level denial of service (application crash) via an attacker-controlled IPv6 URL when the no_proxy environment variable is set.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.1,
              "exploitabilityScore": 1.7,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-9232",
            "epss": 0.02251,
            "percentile": 0.81098,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-9232",
            "cwe": "CWE-125",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.686555
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-9232",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-9232",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35",
            "https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b",
            "https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3",
            "https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf",
            "https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0",
            "https://openssl-library.org/news/secadv/20250930.txt",
            "http://www.openwall.com/lists/oss-security/2025/09/30/5",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-089022.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-485750.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
          ],
          "description": "Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-9232",
              "epss": 0.02251,
              "percentile": 0.81098,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-9232",
              "cwe": "CWE-125",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-9232",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34183",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-34183",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in OpenSSL's QUIC PATH_CHALLENGE handler. A remote attacker can exploit this vulnerability by flooding a QUIC client or server with specially crafted PATH_CHALLENGE frames. This leads to unbounded memory allocation within the local QUIC stack, as the system continuously allocates PATH_RESPONSE frames without them being acknowledged. The primary consequence is a Denial of Service (DoS), causing the affected application to terminate abnormally due to memory exhaustion.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34183",
            "epss": 0.01049,
            "percentile": 0.60755,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34183",
            "cwe": "CWE-1325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.6556249999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34183",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34183",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/5b306efb0b3779dfdd0803b4afc9d08c91f11517",
            "https://github.com/openssl/openssl/commit/7d06955ebe0ecf8adfd4c1e92018586da47ef9ac",
            "https://github.com/openssl/openssl/commit/d2e9efbe4900a373227deb136e8665401404ffac",
            "https://github.com/openssl/openssl/commit/fbaa83859c01ad64f497b757aaf51be7d05ed9eb",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: Remote peer may exhaust heap memory of the QUIC\nserver or client by flooding it with packets containing PATH_CHALLENGE\nframes.\n\nImpact summary: A malicious remote peer can cause an unbounded\nmemory allocation which can lead to an abnormal termination of the\napplication acting as a QUIC client or server and a Denial of Service.\n\nA remote peer may exhaust heap memory by flooding the local\nQUIC stack with PATH_CHALLENGE frames. The local QUIC stack\nallocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives.\nThe allocated PATH_RESPONSE frame gets freed only when the remote\npeer acknowledges reception of the PATH_RESPONSE frame which will\nnot be done by a malicious peer.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by\nthis issue. The QUIC stack is outside of OpenSSL FIPS module\nboundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34183",
              "epss": 0.01049,
              "percentile": 0.60755,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34183",
              "cwe": "CWE-1325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34183",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34183",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-34183",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in OpenSSL's QUIC PATH_CHALLENGE handler. A remote attacker can exploit this vulnerability by flooding a QUIC client or server with specially crafted PATH_CHALLENGE frames. This leads to unbounded memory allocation within the local QUIC stack, as the system continuously allocates PATH_RESPONSE frames without them being acknowledged. The primary consequence is a Denial of Service (DoS), causing the affected application to terminate abnormally due to memory exhaustion.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34183",
            "epss": 0.01049,
            "percentile": 0.60755,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34183",
            "cwe": "CWE-1325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.6556249999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34183",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34183",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/5b306efb0b3779dfdd0803b4afc9d08c91f11517",
            "https://github.com/openssl/openssl/commit/7d06955ebe0ecf8adfd4c1e92018586da47ef9ac",
            "https://github.com/openssl/openssl/commit/d2e9efbe4900a373227deb136e8665401404ffac",
            "https://github.com/openssl/openssl/commit/fbaa83859c01ad64f497b757aaf51be7d05ed9eb",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: Remote peer may exhaust heap memory of the QUIC\nserver or client by flooding it with packets containing PATH_CHALLENGE\nframes.\n\nImpact summary: A malicious remote peer can cause an unbounded\nmemory allocation which can lead to an abnormal termination of the\napplication acting as a QUIC client or server and a Denial of Service.\n\nA remote peer may exhaust heap memory by flooding the local\nQUIC stack with PATH_CHALLENGE frames. The local QUIC stack\nallocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives.\nThe allocated PATH_RESPONSE frame gets freed only when the remote\npeer acknowledges reception of the PATH_RESPONSE frame which will\nnot be done by a malicious peer.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by\nthis issue. The QUIC stack is outside of OpenSSL FIPS module\nboundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34183",
              "epss": 0.01049,
              "percentile": 0.60755,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34183",
              "cwe": "CWE-1325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34183",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-31790",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-31790",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-31790",
            "epss": 0.01202,
            "percentile": 0.65053,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-31790",
            "cwe": "CWE-754",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-2.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-2.el9_8",
              "date": "2026-05-20",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:19218",
            "link": "https://access.redhat.com/errata/RHSA-2026:19218"
          }
        ],
        "risk": 0.6550900000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-31790",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-31790",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac",
            "https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482",
            "https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406",
            "https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790",
            "https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-31790",
              "epss": 0.01202,
              "percentile": 0.65053,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-31790",
              "cwe": "CWE-754",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-31790",
            "versionConstraint": "< 1:3.5.5-2.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-2.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-31790",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-31790",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-31790",
            "epss": 0.01202,
            "percentile": 0.65053,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-31790",
            "cwe": "CWE-754",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.0.7-11.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.0.7-11.el9_8",
              "date": "2026-06-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:27744",
            "link": "https://access.redhat.com/errata/RHSA-2026:27744"
          }
        ],
        "risk": 0.6550900000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-31790",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-31790",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac",
            "https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482",
            "https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406",
            "https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790",
            "https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-31790",
              "epss": 0.01202,
              "percentile": 0.65053,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-31790",
              "cwe": "CWE-754",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl-fips-provider",
              "version": "0:3.0.7-8.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-31790",
            "versionConstraint": "< 0:3.0.7-11.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.0.7-11.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "4f0f0ad93452efa2",
        "name": "openssl-fips-provider",
        "version": "3.0.7-8.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "ASL 2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-fips-provider:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips-provider:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-fips-provider@3.0.7-8.el9?arch=x86_64&distro=rhel-9.7&upstream=openssl-fips-provider-3.0.7-8.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-31790",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-31790",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-31790",
            "epss": 0.01202,
            "percentile": 0.65053,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-31790",
            "cwe": "CWE-754",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.0.7-11.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.0.7-11.el9_8",
              "date": "2026-06-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:27744",
            "link": "https://access.redhat.com/errata/RHSA-2026:27744"
          }
        ],
        "risk": 0.6550900000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-31790",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-31790",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac",
            "https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482",
            "https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406",
            "https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790",
            "https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-31790",
              "epss": 0.01202,
              "percentile": 0.65053,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-31790",
              "cwe": "CWE-754",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl-fips-provider",
              "version": "3.0.7-8.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-31790",
            "versionConstraint": "< 0:3.0.7-11.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.0.7-11.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "039e508ce9d5da38",
        "name": "openssl-fips-provider-so",
        "version": "3.0.7-8.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "ASL 2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-fips-provider-so:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips-provider-so:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider_so:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider_so:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips-provider:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips-provider:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-8.el9?arch=x86_64&distro=rhel-9.7&upstream=openssl-fips-provider-3.0.7-8.el9.src.rpm",
        "upstreams": [
          {
            "name": "openssl-fips-provider",
            "version": "3.0.7-8.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-31790",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-31790",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in openssl. Applications that use RSASVE key encapsulation, a method for securely exchanging encryption keys, may inadvertently expose sensitive data. This vulnerability arises when an application processes a malicious, invalid RSA public key provided by an attacker without proper validation. Consequently, the application might send the contents of an uninitialized memory buffer, which could contain confidential information, to the attacker.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-31790",
            "epss": 0.01202,
            "percentile": 0.65053,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-31790",
            "cwe": "CWE-754",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-2.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-2.el9_8",
              "date": "2026-05-20",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:19218",
            "link": "https://access.redhat.com/errata/RHSA-2026:19218"
          }
        ],
        "risk": 0.6550900000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-31790",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-31790",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac",
            "https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482",
            "https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406",
            "https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790",
            "https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-31790",
              "epss": 0.01202,
              "percentile": 0.65053,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-31790",
              "cwe": "CWE-754",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-31790",
            "versionConstraint": "< 1:3.5.5-2.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-2.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-28390",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-28390",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in OpenSSL. A remote attacker could exploit this vulnerability by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message. During the processing of a KeyTransportRecipientInfo with RSA-OAEP encryption, the system attempts to access an optional parameter field without first verifying its presence. This leads to a NULL pointer dereference, which can cause applications processing the attacker-controlled CMS data to crash, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-28390",
            "epss": 0.01027,
            "percentile": 0.60095,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-28390",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-3.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-3.el9_8",
              "date": "2026-06-02",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:22312",
            "link": "https://access.redhat.com/errata/RHSA-2026:22312"
          }
        ],
        "risk": 0.641875
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-28390",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-28390",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc",
            "https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6",
            "https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4",
            "https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788",
            "https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-28390",
              "epss": 0.01027,
              "percentile": 0.60095,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-28390",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-28390",
            "versionConstraint": "< 1:3.5.5-3.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-3.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-28390",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-28390",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in OpenSSL. A remote attacker could exploit this vulnerability by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message. During the processing of a KeyTransportRecipientInfo with RSA-OAEP encryption, the system attempts to access an optional parameter field without first verifying its presence. This leads to a NULL pointer dereference, which can cause applications processing the attacker-controlled CMS data to crash, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-28390",
            "epss": 0.01027,
            "percentile": 0.60095,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-28390",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-3.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-3.el9_8",
              "date": "2026-06-02",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:22312",
            "link": "https://access.redhat.com/errata/RHSA-2026:22312"
          }
        ],
        "risk": 0.641875
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-28390",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-28390",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc",
            "https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6",
            "https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4",
            "https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788",
            "https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-28390",
              "epss": 0.01027,
              "percentile": 0.60095,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-28390",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-28390",
            "versionConstraint": "< 1:3.5.5-3.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-3.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42764",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42764",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the OpenSSL QUIC (Quick UDP Internet Connections) server. A remote attacker could send a specially crafted QUIC initial packet with an invalid token. If the server's address validation is explicitly disabled, this could lead to a NULL pointer dereference, causing the server process to terminate abnormally and resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42764",
            "epss": 0.01165,
            "percentile": 0.64067,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42764",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.6349250000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42764",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42764",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/5e3ed291b8af0b03d5d3b9e56a1da69a187e9729",
            "https://github.com/openssl/openssl/commit/a45a0aba8095682c88ff4fc4a784892b8c6f0677",
            "https://github.com/openssl/openssl/commit/bf29a458c1a231eca87e384c62b9c2553fa57a91",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: Receiving a QUIC initial packet with an invalid token may\ntrigger a NULL pointer dereference in the OpenSSL QUIC server with\naddress validation disabled.\n\nImpact summary: NULL pointer dereference typically causes abnormal termination\nof the affected QUIC server process and a Denial of Service.\n\nIf the address validation is disabled in the OpenSSL QUIC server\nimplementation, an attacker can crash the server by sending an initial\npacket with an invalid or expired token.\n\nBy default, the client address validation is enabled in the OpenSSL QUIC server\nimplementation, which makes the default configuration not vulnerable\nto this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with\nthe SSL_new_listener() call, the address validation is disabled making the\nvulnerable code reachable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42764",
              "epss": 0.01165,
              "percentile": 0.64067,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42764",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42764",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42764",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42764",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the OpenSSL QUIC (Quick UDP Internet Connections) server. A remote attacker could send a specially crafted QUIC initial packet with an invalid token. If the server's address validation is explicitly disabled, this could lead to a NULL pointer dereference, causing the server process to terminate abnormally and resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42764",
            "epss": 0.01165,
            "percentile": 0.64067,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42764",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.6349250000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42764",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42764",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/5e3ed291b8af0b03d5d3b9e56a1da69a187e9729",
            "https://github.com/openssl/openssl/commit/a45a0aba8095682c88ff4fc4a784892b8c6f0677",
            "https://github.com/openssl/openssl/commit/bf29a458c1a231eca87e384c62b9c2553fa57a91",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: Receiving a QUIC initial packet with an invalid token may\ntrigger a NULL pointer dereference in the OpenSSL QUIC server with\naddress validation disabled.\n\nImpact summary: NULL pointer dereference typically causes abnormal termination\nof the affected QUIC server process and a Denial of Service.\n\nIf the address validation is disabled in the OpenSSL QUIC server\nimplementation, an attacker can crash the server by sending an initial\npacket with an invalid or expired token.\n\nBy default, the client address validation is enabled in the OpenSSL QUIC server\nimplementation, which makes the default configuration not vulnerable\nto this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with\nthe SSL_new_listener() call, the address validation is disabled making the\nvulnerable code reachable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42764",
              "epss": 0.01165,
              "percentile": 0.64067,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42764",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42764",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-11053",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-11053",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in curl. A logic error when processing credentials from the .netrc file while performing redirects allows the transfer of credentials from the original host to the followed-to host under certain circumstances, leaking the credentials to the followed-to host.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-11053",
            "epss": 0.01378,
            "percentile": 0.6926,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.6132100000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-11053",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-11053",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://curl.se/docs/CVE-2024-11053.html",
            "https://curl.se/docs/CVE-2024-11053.json",
            "https://hackerone.com/reports/2829063",
            "http://www.openwall.com/lists/oss-security/2024/12/11/1",
            "https://security.netapp.com/advisory/ntap-20250124-0012/",
            "https://security.netapp.com/advisory/ntap-20250131-0003/",
            "https://security.netapp.com/advisory/ntap-20250131-0004/"
          ],
          "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 3.4,
                "exploitabilityScore": 1.7,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-11053",
              "epss": 0.01378,
              "percentile": 0.6926,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-11053",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-11053",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-11053",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in curl. A logic error when processing credentials from the .netrc file while performing redirects allows the transfer of credentials from the original host to the followed-to host under certain circumstances, leaking the credentials to the followed-to host.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-11053",
            "epss": 0.01378,
            "percentile": 0.6926,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.6132100000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-11053",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-11053",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://curl.se/docs/CVE-2024-11053.html",
            "https://curl.se/docs/CVE-2024-11053.json",
            "https://hackerone.com/reports/2829063",
            "http://www.openwall.com/lists/oss-security/2024/12/11/1",
            "https://security.netapp.com/advisory/ntap-20250124-0012/",
            "https://security.netapp.com/advisory/ntap-20250131-0003/",
            "https://security.netapp.com/advisory/ntap-20250131-0004/"
          ],
          "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 3.4,
                "exploitabilityScore": 1.7,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-11053",
              "epss": 0.01378,
              "percentile": 0.6926,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-11053",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-33845",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-33845",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-33845",
            "epss": 0.00805,
            "percentile": 0.53074,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-33845",
            "cwe": "CWE-191",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-33845",
            "cwe": "CWE-191",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.6037499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-33845",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-33845",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:34372",
            "https://access.redhat.com/errata/RHSA-2026:36004",
            "https://access.redhat.com/errata/RHSA-2026:36005",
            "https://access.redhat.com/errata/RHSA-2026:36006",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/security/cve/CVE-2026-33845",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2450624",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33845.json"
          ],
          "description": "A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-33845",
              "epss": 0.00805,
              "percentile": 0.53074,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-33845",
              "cwe": "CWE-191",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-33845",
              "cwe": "CWE-191",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-33845",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-2100",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-2100",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-2100",
            "epss": 0.0116,
            "percentile": 0.63884,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-2100",
            "cwe": "CWE-824",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:0.26.2-1.el9"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:0.26.2-1.el9",
              "date": "2026-05-20",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:18599",
            "link": "https://access.redhat.com/errata/RHSA-2026:18599"
          }
        ],
        "risk": 0.5974
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-2100",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-2100",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:18143",
            "https://access.redhat.com/errata/RHSA-2026:18599",
            "https://access.redhat.com/errata/RHSA-2026:21275",
            "https://access.redhat.com/errata/RHSA-2026:22634",
            "https://access.redhat.com/errata/RHSA-2026:27998",
            "https://access.redhat.com/errata/RHSA-2026:7065",
            "https://access.redhat.com/security/cve/CVE-2026-2100",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2437308",
            "https://github.com/p11-glue/p11-kit/pull/740",
            "https://github.com/p11-glue/p11-kit/releases/tag/0.26.2"
          ],
          "description": "A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-2100",
              "epss": 0.0116,
              "percentile": 0.63884,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-2100",
              "cwe": "CWE-824",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "p11-kit",
              "version": "0:0.25.3-3.el9_5"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-2100",
            "versionConstraint": "< 0:0.26.2-1.el9 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:0.26.2-1.el9"
          }
        }
      ],
      "artifact": {
        "id": "39edf0f240a77402",
        "name": "p11-kit",
        "version": "0.25.3-3.el9_5",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD-3-Clause"
        ],
        "cpes": [
          "cpe:2.3:a:p11-kit:p11-kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11-kit:p11_kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit:p11-kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit:p11_kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:p11-kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:p11_kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11:p11-kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11:p11_kit:0.25.3-3.el9_5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/p11-kit@0.25.3-3.el9_5?arch=x86_64&distro=rhel-9.7&upstream=p11-kit-0.25.3-3.el9_5.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-2100",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-2100",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-2100",
            "epss": 0.0116,
            "percentile": 0.63884,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-2100",
            "cwe": "CWE-824",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:0.26.2-1.el9"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:0.26.2-1.el9",
              "date": "2026-05-20",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:18599",
            "link": "https://access.redhat.com/errata/RHSA-2026:18599"
          }
        ],
        "risk": 0.5974
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-2100",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-2100",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:18143",
            "https://access.redhat.com/errata/RHSA-2026:18599",
            "https://access.redhat.com/errata/RHSA-2026:21275",
            "https://access.redhat.com/errata/RHSA-2026:22634",
            "https://access.redhat.com/errata/RHSA-2026:27998",
            "https://access.redhat.com/errata/RHSA-2026:7065",
            "https://access.redhat.com/security/cve/CVE-2026-2100",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2437308",
            "https://github.com/p11-glue/p11-kit/pull/740",
            "https://github.com/p11-glue/p11-kit/releases/tag/0.26.2"
          ],
          "description": "A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-2100",
              "epss": 0.0116,
              "percentile": 0.63884,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-2100",
              "cwe": "CWE-824",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "p11-kit",
              "version": "0.25.3-3.el9_5"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-2100",
            "versionConstraint": "< 0:0.26.2-1.el9 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:0.26.2-1.el9"
          }
        }
      ],
      "artifact": {
        "id": "546bedf3e2fa6b85",
        "name": "p11-kit-trust",
        "version": "0.25.3-3.el9_5",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD-3-Clause"
        ],
        "cpes": [
          "cpe:2.3:a:p11-kit-trust:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11-kit-trust:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit_trust:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit_trust:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11-kit:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11-kit:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/p11-kit-trust@0.25.3-3.el9_5?arch=x86_64&distro=rhel-9.7&upstream=p11-kit-0.25.3-3.el9_5.src.rpm",
        "upstreams": [
          {
            "name": "p11-kit",
            "version": "0.25.3-3.el9_5"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-13151",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-13151",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libtasn1. A remote attacker could exploit a stack-based buffer overflow vulnerability in the `asn1_expend_octet_string` function. This occurs due to a failure in validating the size of input data. Successful exploitation can lead to a Denial of Service (DoS) condition, making the affected system or application unavailable.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-13151",
            "epss": 0.01109,
            "percentile": 0.62532,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-13151",
            "cwe": "CWE-787",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [
            "0:4.16.0-10.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:4.16.0-10.el9_8",
              "date": "2026-06-24",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:28253",
            "link": "https://access.redhat.com/errata/RHSA-2026:28253"
          }
        ],
        "risk": 0.4935050000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-13151",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-13151",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://gitlab.com/gnutls/libtasn1",
            "https://gitlab.com/gnutls/libtasn1/-/merge_requests/121",
            "http://www.openwall.com/lists/oss-security/2026/01/08/5",
            "https://www.kb.cert.org/vuls/id/271649"
          ],
          "description": "Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-13151",
              "epss": 0.01109,
              "percentile": 0.62532,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-13151",
              "cwe": "CWE-787",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libtasn1",
              "version": "0:4.16.0-9.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-13151",
            "versionConstraint": "< 0:4.16.0-10.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:4.16.0-10.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "3761cee678a57b02",
        "name": "libtasn1",
        "version": "4.16.0-9.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libtasn1:libtasn1:4.16.0-9.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libtasn1:4.16.0-9.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libtasn1@4.16.0-9.el9?arch=x86_64&distro=rhel-9.7&upstream=libtasn1-4.16.0-9.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-41996",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-41996",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server's public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-41996",
            "epss": 0.01083,
            "percentile": 0.61757,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-41996",
            "cwe": "CWE-295",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.481935
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-41996",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-41996",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://dheatattack.gitlab.io/details/",
            "https://dheatattack.gitlab.io/faq/",
            "https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1",
            "https://cert-portal.siemens.com/productcert/html/ssa-089022.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
          ],
          "description": "Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-41996",
              "epss": 0.01083,
              "percentile": 0.61757,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-41996",
              "cwe": "CWE-295",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-41996",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-41996",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-41996",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server's public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-41996",
            "epss": 0.01083,
            "percentile": 0.61757,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-41996",
            "cwe": "CWE-295",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.481935
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-41996",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-41996",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://dheatattack.gitlab.io/details/",
            "https://dheatattack.gitlab.io/faq/",
            "https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1",
            "https://cert-portal.siemens.com/productcert/html/ssa-089022.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
          ],
          "description": "Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-41996",
              "epss": 0.01083,
              "percentile": 0.61757,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-41996",
              "cwe": "CWE-295",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-41996",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5260",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5260",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 8.2,
              "exploitabilityScore": 3.9,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5260",
            "epss": 0.00727,
            "percentile": 0.50443,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5260",
            "cwe": "CWE-126",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.47981999999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5260",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5260",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:40762",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/security/cve/CVE-2026-5260",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467450",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-10"
          ],
          "description": "A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 8.2,
                "exploitabilityScore": 3.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5260",
              "epss": 0.00727,
              "percentile": 0.50443,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5260",
              "cwe": "CWE-126",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5260",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-28388",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-28388",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-28388",
            "epss": 0.01059,
            "percentile": 0.61046,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-28388",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.4712550000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-28388",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-28388",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e",
            "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139",
            "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3",
            "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8",
            "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-28388",
              "epss": 0.01059,
              "percentile": 0.61046,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-28388",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-28388",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-28388",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-28388",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-28388",
            "epss": 0.01059,
            "percentile": 0.61046,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-28388",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.4712550000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-28388",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-28388",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e",
            "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139",
            "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3",
            "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8",
            "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-28388",
              "epss": 0.01059,
              "percentile": 0.61046,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-28388",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-28388",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2022-41409",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2022-41409",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in PCRE2, where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2022-41409",
            "epss": 0.01121,
            "percentile": 0.62867,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2022-41409",
            "cwe": "CWE-190",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.465215
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2022-41409",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2022-41409",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35",
            "https://github.com/PCRE2Project/pcre2/issues/141"
          ],
          "description": "Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2022-41409",
              "epss": 0.01121,
              "percentile": 0.62867,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2022-41409",
              "cwe": "CWE-190",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "pcre2",
              "version": "0:10.40-6.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2022-41409",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "d52857c4436af57f",
        "name": "pcre2",
        "version": "10.40-6.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.7&upstream=pcre2-10.40-6.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2022-41409",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2022-41409",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in PCRE2, where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2022-41409",
            "epss": 0.01121,
            "percentile": 0.62867,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2022-41409",
            "cwe": "CWE-190",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.465215
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2022-41409",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2022-41409",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35",
            "https://github.com/PCRE2Project/pcre2/issues/141"
          ],
          "description": "Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2022-41409",
              "epss": 0.01121,
              "percentile": 0.62867,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2022-41409",
              "cwe": "CWE-190",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "pcre2",
              "version": "10.40-6.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2022-41409",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "79b3a388130aa9b9",
        "name": "pcre2-syntax",
        "version": "10.40-6.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.7&upstream=pcre2-10.40-6.el9.src.rpm",
        "upstreams": [
          {
            "name": "pcre2",
            "version": "10.40-6.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "noarch"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8925",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-8925",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in curl. The logic handling SASL (Simple Authentication and Security Layer) authentication could lead to a double-free vulnerability. This occurs because the GSASL context may be deallocated twice without clearing the pointer, potentially leading to memory corruption. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.3,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8925",
            "epss": 0.00592,
            "percentile": 0.44826,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-8925",
            "cwe": "CWE-415",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.46176000000000006
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8925",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8925",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-8925.html",
            "https://curl.se/docs/CVE-2026-8925.json",
            "https://hackerone.com/reports/3735193"
          ],
          "description": "The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8925",
              "epss": 0.00592,
              "percentile": 0.44826,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-8925",
              "cwe": "CWE-415",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8925",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8925",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-8925",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in curl. The logic handling SASL (Simple Authentication and Security Layer) authentication could lead to a double-free vulnerability. This occurs because the GSASL context may be deallocated twice without clearing the pointer, potentially leading to memory corruption. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.3,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8925",
            "epss": 0.00592,
            "percentile": 0.44826,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-8925",
            "cwe": "CWE-415",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.46176000000000006
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8925",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8925",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-8925.html",
            "https://curl.se/docs/CVE-2026-8925.json",
            "https://hackerone.com/reports/3735193"
          ],
          "description": "The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8925",
              "epss": 0.00592,
              "percentile": 0.44826,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-8925",
              "cwe": "CWE-415",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8925",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-28389",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-28389",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-28389",
            "epss": 0.01027,
            "percentile": 0.60095,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-28389",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.457015
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-28389",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-28389",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5",
            "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616",
            "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f",
            "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a",
            "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-28389",
              "epss": 0.01027,
              "percentile": 0.60095,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-28389",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-28389",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-28389",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-28389",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-28389",
            "epss": 0.01027,
            "percentile": 0.60095,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-28389",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.457015
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-28389",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-28389",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5",
            "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616",
            "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f",
            "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a",
            "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-28389",
              "epss": 0.01027,
              "percentile": 0.60095,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-28389",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-28389",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-50495",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2023-50495",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry().",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2023-50495",
            "epss": 0.00962,
            "percentile": 0.58007,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.45694999999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-50495",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-50495",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/",
            "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html",
            "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html",
            "https://security.netapp.com/advisory/ntap-20240119-0008/",
            "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"
          ],
          "description": "NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-50495",
              "epss": 0.00962,
              "percentile": 0.58007,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "ncurses",
              "version": "6.2-12.20210508.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-50495",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "cb11b32d6ce6627c",
        "name": "ncurses-base",
        "version": "6.2-12.20210508.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:ncurses-base:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:ncurses-base:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:ncurses_base:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:ncurses_base:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:ncurses:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:ncurses:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=rhel-9.7&upstream=ncurses-6.2-12.20210508.el9.src.rpm",
        "upstreams": [
          {
            "name": "ncurses",
            "version": "6.2-12.20210508.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "noarch"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-50495",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2023-50495",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry().",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2023-50495",
            "epss": 0.00962,
            "percentile": 0.58007,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.45694999999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-50495",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-50495",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/",
            "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html",
            "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html",
            "https://security.netapp.com/advisory/ntap-20240119-0008/",
            "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"
          ],
          "description": "NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-50495",
              "epss": 0.00962,
              "percentile": 0.58007,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "ncurses",
              "version": "6.2-12.20210508.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-50495",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "9dc1b34cdde2c695",
        "name": "ncurses-libs",
        "version": "6.2-12.20210508.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:ncurses-libs:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:ncurses-libs:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:ncurses_libs:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:ncurses_libs:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:ncurses:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:ncurses:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=rhel-9.7&upstream=ncurses-6.2-12.20210508.el9.src.rpm",
        "upstreams": [
          {
            "name": "ncurses",
            "version": "6.2-12.20210508.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11352",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-11352",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in curl and libcurl. A malicious HTTP/3 server can exploit an issue in the QUIC UDP receive function by continuously streaming empty UDP datagrams. This can lead to a remote denial of service (DoS) against a curl or libcurl client, as the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, causing the client to indefinitely stall.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-11352",
            "epss": 0.00577,
            "percentile": 0.44159,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11352",
            "cwe": "CWE-835",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.43274999999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11352",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11352",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-11352.html",
            "https://curl.se/docs/CVE-2026-11352.json",
            "https://hackerone.com/reports/3783438"
          ],
          "description": "An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server\nto trigger a remote denial of service against a curl or libcurl client.\nBecause the helper function discards zero-length UDP datagrams before counting\nthem toward the per-call packet budget, a connected QUIC peer can continuously\nstream empty datagrams to indefinitely stall the client.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11352",
              "epss": 0.00577,
              "percentile": 0.44159,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11352",
              "cwe": "CWE-835",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11352",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11352",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-11352",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in curl and libcurl. A malicious HTTP/3 server can exploit an issue in the QUIC UDP receive function by continuously streaming empty UDP datagrams. This can lead to a remote denial of service (DoS) against a curl or libcurl client, as the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, causing the client to indefinitely stall.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-11352",
            "epss": 0.00577,
            "percentile": 0.44159,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11352",
            "cwe": "CWE-835",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.43274999999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11352",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11352",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-11352.html",
            "https://curl.se/docs/CVE-2026-11352.json",
            "https://hackerone.com/reports/3783438"
          ],
          "description": "An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server\nto trigger a remote denial of service against a curl or libcurl client.\nBecause the helper function discards zero-length UDP datagrams before counting\nthem toward the per-call packet budget, a connected QUIC peer can continuously\nstream empty datagrams to indefinitely stall the client.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11352",
              "epss": 0.00577,
              "percentile": 0.44159,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11352",
              "cwe": "CWE-835",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11352",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-0990",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-0990",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-0990",
            "epss": 0.00789,
            "percentile": 0.52533,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-0990",
            "cwe": "CWE-674",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.43000499999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-0990",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-0990",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:7519",
            "https://access.redhat.com/security/cve/CVE-2026-0990",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2429959",
            "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"
          ],
          "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-0990",
              "epss": 0.00789,
              "percentile": 0.52533,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-0990",
              "cwe": "CWE-674",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libxml2",
              "version": "0:2.9.13-14.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-0990",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a840257087cebda4",
        "name": "libxml2",
        "version": "2.9.13-14.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libxml2-2.9.13-14.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-45445",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-45445",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in OpenSSL. Applications that use the AES-OCB encryption method with a specific one-shot interface (EVP_Cipher()) will have their provided Initialization Vector (IV) silently discarded. This leads to the same internal cryptographic value being used repeatedly, which compromises the confidentiality of encrypted data. Additionally, this issue allows for the universal forgery of authentication tags, undermining the integrity of communications.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 9.1,
              "exploitabilityScore": 3.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-45445",
            "epss": 0.00603,
            "percentile": 0.4534,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-45445",
            "cwe": "CWE-325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.42511499999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-45445",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-45445",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451",
            "https://github.com/openssl/openssl/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7",
            "https://github.com/openssl/openssl/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af",
            "https://github.com/openssl/openssl/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c",
            "https://github.com/openssl/openssl/commit/983d54b5cce8d16147548ed1a37892d1720bbab6",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: When an application drives an AES-OCB context through the\npublic EVP_Cipher() one-shot interface, the application-supplied\ninitialisation vector (IV) is silently discarded.\n\nImpact summary: Every message encrypted under the same key uses the\nsame effective nonce regardless of the IV supplied by the caller,\nresulting in (key, nonce) reuse and loss of confidentiality.  If the\nsame code path is used to compute the authentication tag, the tag\ndepends only on the (key, IV) pair and not on the plaintext or\nciphertext, allowing universal forgery of arbitrary ciphertext from a\nsingle captured message.\n\nOpenSSL provides two ways to drive a cipher: the documented streaming\ninterface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level\none-shot, EVP_Cipher(), whose documentation explicitly recommends\nagainst use by applications in favour of EVP_CipherUpdate() and\nEVP_CipherFinal_ex().  The OCB provider's streaming handler flushes\nthe application-supplied IV into the OCB context before processing\ndata; the one-shot handler did not.  Every call to EVP_Cipher() on an\nAES-OCB context therefore ran with the all-zero key-derived offset\nstate left by cipher initialisation, regardless of the caller's IV.\n\nIf EVP_EncryptFinal_ex() is subsequently used to obtain the\nauthentication tag, the deferred IV setup runs at that point and\nclears the running checksum that should have been accumulated over the\nplaintext.  The resulting tag is a function of (key, IV) only and\nverifies against any ciphertext produced under the same (key, IV)\npair.\n\nThe OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a\nTLS cipher suite, and libssl does not call EVP_Cipher() in any case.\nApplications that drive AES-OCB through the documented streaming AEAD\nAPI (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only\napplications that combine the AES-OCB cipher with the EVP_Cipher()\none-shot API are vulnerable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-45445",
              "epss": 0.00603,
              "percentile": 0.4534,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-45445",
              "cwe": "CWE-325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-45445",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-45445",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-45445",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in OpenSSL. Applications that use the AES-OCB encryption method with a specific one-shot interface (EVP_Cipher()) will have their provided Initialization Vector (IV) silently discarded. This leads to the same internal cryptographic value being used repeatedly, which compromises the confidentiality of encrypted data. Additionally, this issue allows for the universal forgery of authentication tags, undermining the integrity of communications.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 9.1,
              "exploitabilityScore": 3.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-45445",
            "epss": 0.00603,
            "percentile": 0.4534,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-45445",
            "cwe": "CWE-325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.42511499999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-45445",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-45445",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451",
            "https://github.com/openssl/openssl/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7",
            "https://github.com/openssl/openssl/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af",
            "https://github.com/openssl/openssl/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c",
            "https://github.com/openssl/openssl/commit/983d54b5cce8d16147548ed1a37892d1720bbab6",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: When an application drives an AES-OCB context through the\npublic EVP_Cipher() one-shot interface, the application-supplied\ninitialisation vector (IV) is silently discarded.\n\nImpact summary: Every message encrypted under the same key uses the\nsame effective nonce regardless of the IV supplied by the caller,\nresulting in (key, nonce) reuse and loss of confidentiality.  If the\nsame code path is used to compute the authentication tag, the tag\ndepends only on the (key, IV) pair and not on the plaintext or\nciphertext, allowing universal forgery of arbitrary ciphertext from a\nsingle captured message.\n\nOpenSSL provides two ways to drive a cipher: the documented streaming\ninterface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level\none-shot, EVP_Cipher(), whose documentation explicitly recommends\nagainst use by applications in favour of EVP_CipherUpdate() and\nEVP_CipherFinal_ex().  The OCB provider's streaming handler flushes\nthe application-supplied IV into the OCB context before processing\ndata; the one-shot handler did not.  Every call to EVP_Cipher() on an\nAES-OCB context therefore ran with the all-zero key-derived offset\nstate left by cipher initialisation, regardless of the caller's IV.\n\nIf EVP_EncryptFinal_ex() is subsequently used to obtain the\nauthentication tag, the deferred IV setup runs at that point and\nclears the running checksum that should have been accumulated over the\nplaintext.  The resulting tag is a function of (key, IV) only and\nverifies against any ciphertext produced under the same (key, IV)\npair.\n\nThe OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a\nTLS cipher suite, and libssl does not call EVP_Cipher() in any case.\nApplications that drive AES-OCB through the documented streaming AEAD\nAPI (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only\napplications that combine the AES-OCB cipher with the EVP_Cipher()\none-shot API are vulnerable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-45445",
              "epss": 0.00603,
              "percentile": 0.4534,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-45445",
              "cwe": "CWE-325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-45445",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42766",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42766",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.7,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42766",
            "epss": 0.00996,
            "percentile": 0.59124,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42766",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.41334000000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42766",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42766",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce",
            "https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4",
            "https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7",
            "https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4",
            "https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42766",
              "epss": 0.00996,
              "percentile": 0.59124,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42766",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42766",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42766",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42766",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.7,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42766",
            "epss": 0.00996,
            "percentile": 0.59124,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42766",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.41334000000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42766",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42766",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce",
            "https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4",
            "https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7",
            "https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4",
            "https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42766",
              "epss": 0.00996,
              "percentile": 0.59124,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42766",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42766",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34180",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-34180",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34180",
            "epss": 0.01025,
            "percentile": 0.60056,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34180",
            "cwe": "CWE-125",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.41000000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34180",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34180",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d",
            "https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83",
            "https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff",
            "https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43",
            "https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34180",
              "epss": 0.01025,
              "percentile": 0.60056,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34180",
              "cwe": "CWE-125",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34180",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34180",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-34180",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34180",
            "epss": 0.01025,
            "percentile": 0.60056,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34180",
            "cwe": "CWE-125",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.41000000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34180",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34180",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d",
            "https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83",
            "https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff",
            "https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43",
            "https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34180",
              "epss": 0.01025,
              "percentile": 0.60056,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34180",
              "cwe": "CWE-125",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34180",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-14087",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-14087",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "metrics": {
              "baseScore": 5.6,
              "exploitabilityScore": 2.3,
              "impactScore": 3.4
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-14087",
            "epss": 0.00767,
            "percentile": 0.5182,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-14087",
            "cwe": "CWE-190",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.68.4-18.el9_7.2"
          ],
          "state": "fixed"
        },
        "advisories": [
          {
            "id": "RHSA-2026:15971",
            "link": "https://access.redhat.com/errata/RHSA-2026:15971"
          }
        ],
        "risk": 0.40651000000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-14087",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-14087",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:15953",
            "https://access.redhat.com/errata/RHSA-2026:15969",
            "https://access.redhat.com/errata/RHSA-2026:15971",
            "https://access.redhat.com/errata/RHSA-2026:19148",
            "https://access.redhat.com/errata/RHSA-2026:19361",
            "https://access.redhat.com/errata/RHSA-2026:19452",
            "https://access.redhat.com/errata/RHSA-2026:19457",
            "https://access.redhat.com/errata/RHSA-2026:19459",
            "https://access.redhat.com/errata/RHSA-2026:19460",
            "https://access.redhat.com/errata/RHSA-2026:19523",
            "https://access.redhat.com/errata/RHSA-2026:19524",
            "https://access.redhat.com/errata/RHSA-2026:19565",
            "https://access.redhat.com/errata/RHSA-2026:19566",
            "https://access.redhat.com/errata/RHSA-2026:19567",
            "https://access.redhat.com/errata/RHSA-2026:21275",
            "https://access.redhat.com/errata/RHSA-2026:22634",
            "https://access.redhat.com/errata/RHSA-2026:25096",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:7461",
            "https://access.redhat.com/security/cve/CVE-2025-14087",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2419093",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3834"
          ],
          "description": "A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 5.6,
                "exploitabilityScore": 2.3,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-14087",
              "epss": 0.00767,
              "percentile": 0.5182,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-14087",
              "cwe": "CWE-190",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-14087",
            "versionConstraint": "< 0:2.68.4-18.el9_7.2 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.68.4-18.el9_7.2"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2022-27943",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2022-27943",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 1.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2022-27943",
            "epss": 0.00892,
            "percentile": 0.55776,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2022-27943",
            "cwe": "CWE-674",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.3791000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2022-27943",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039",
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
          ],
          "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 8.6,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2022-27943",
              "epss": 0.00892,
              "percentile": 0.55776,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2022-27943",
              "cwe": "CWE-674",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gcc",
              "version": "11.5.0-11.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2022-27943",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "06e2c48d975ea1da",
        "name": "libgcc",
        "version": "11.5.0-11.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libgcc:libgcc:11.5.0-11.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libgcc:11.5.0-11.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libgcc@11.5.0-11.el9?arch=x86_64&distro=rhel-9.7&upstream=gcc-11.5.0-11.el9.src.rpm",
        "upstreams": [
          {
            "name": "gcc",
            "version": "11.5.0-11.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2022-27943",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2022-27943",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 1.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2022-27943",
            "epss": 0.00892,
            "percentile": 0.55776,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2022-27943",
            "cwe": "CWE-674",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.3791000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2022-27943",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039",
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
          ],
          "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 8.6,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2022-27943",
              "epss": 0.00892,
              "percentile": 0.55776,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2022-27943",
              "cwe": "CWE-674",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gcc",
              "version": "11.5.0-11.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2022-27943",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "e66b7275c6659e9c",
        "name": "libstdc++",
        "version": "11.5.0-11.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.5.0-11.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libstdc\\+\\+:11.5.0-11.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-11.el9?arch=x86_64&distro=rhel-9.7&upstream=gcc-11.5.0-11.el9.src.rpm",
        "upstreams": [
          {
            "name": "gcc",
            "version": "11.5.0-11.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42015",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42015",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42015",
            "epss": 0.00727,
            "percentile": 0.50439,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42015",
            "cwe": "CWE-193",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.37440500000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42015",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42015",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-42015",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467678",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-11"
          ],
          "description": "A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42015",
              "epss": 0.00727,
              "percentile": 0.50439,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42015",
              "cwe": "CWE-193",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42015",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6253",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-6253",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy's credentials. This improper credential management (CWE-522) may allow an attacker to gain unauthorized access or information by intercepting these disclosed credentials.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.7,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6253",
            "epss": 0.00719,
            "percentile": 0.50163,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6253",
            "cwe": "CWE-522",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.37028500000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6253",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-6253.html",
            "https://curl.se/docs/CVE-2026-6253.json",
            "https://hackerone.com/reports/3669637",
            "http://www.openwall.com/lists/oss-security/2026/04/29/11"
          ],
          "description": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6253",
              "epss": 0.00719,
              "percentile": 0.50163,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6253",
              "cwe": "CWE-522",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6253",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6253",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-6253",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy's credentials. This improper credential management (CWE-522) may allow an attacker to gain unauthorized access or information by intercepting these disclosed credentials.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.7,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6253",
            "epss": 0.00719,
            "percentile": 0.50163,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6253",
            "cwe": "CWE-522",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.37028500000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6253",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-6253.html",
            "https://curl.se/docs/CVE-2026-6253.json",
            "https://hackerone.com/reports/3669637",
            "http://www.openwall.com/lists/oss-security/2026/04/29/11"
          ],
          "description": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6253",
              "epss": 0.00719,
              "percentile": 0.50163,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6253",
              "cwe": "CWE-522",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6253",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11586",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-11586",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in curl. A malicious server can exploit this vulnerability by sending rapid, sequential WebSocket PING messages. Due to a lack of an upper bound on memory allocation for unacknowledged frames, curl can be forced to exhaust all available memory, leading to a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-11586",
            "epss": 0.00491,
            "percentile": 0.39443,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11586",
            "cwe": "CWE-770",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.36825
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11586",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11586",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-11586.html",
            "https://curl.se/docs/CVE-2026-11586.json",
            "https://hackerone.com/reports/3788931"
          ],
          "description": "By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11586",
              "epss": 0.00491,
              "percentile": 0.39443,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11586",
              "cwe": "CWE-770",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11586",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11586",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-11586",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in curl. A malicious server can exploit this vulnerability by sending rapid, sequential WebSocket PING messages. Due to a lack of an upper bound on memory allocation for unacknowledged frames, curl can be forced to exhaust all available memory, leading to a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-11586",
            "epss": 0.00491,
            "percentile": 0.39443,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11586",
            "cwe": "CWE-770",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.36825
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11586",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11586",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-11586.html",
            "https://curl.se/docs/CVE-2026-11586.json",
            "https://hackerone.com/reports/3788931"
          ],
          "description": "By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11586",
              "epss": 0.00491,
              "percentile": 0.39443,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11586",
              "cwe": "CWE-770",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11586",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-45322",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2023-45322",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libxml2. In an out-of-memory condition or when limiting the memory allocation, processing a XML document using the HTML parser may result in a use-after-free vulnerability.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2023-45322",
            "epss": 0.00826,
            "percentile": 0.53712,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2023-45322",
            "cwe": "CWE-416",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.36757000000000006
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-45322",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-45322",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "http://www.openwall.com/lists/oss-security/2023/10/06/5",
            "https://gitlab.gnome.org/GNOME/libxml2/-/issues/344",
            "https://gitlab.gnome.org/GNOME/libxml2/-/issues/583",
            "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
          ],
          "description": "libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is \"I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail.\"",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-45322",
              "epss": 0.00826,
              "percentile": 0.53712,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2023-45322",
              "cwe": "CWE-416",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libxml2",
              "version": "0:2.9.13-14.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-45322",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a840257087cebda4",
        "name": "libxml2",
        "version": "2.9.13-14.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libxml2-2.9.13-14.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6732",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-6732",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6732",
            "epss": 0.00632,
            "percentile": 0.4666,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6732",
            "cwe": "CWE-843",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.36339999999999995
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6732",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6732",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:11503",
            "https://access.redhat.com/security/cve/CVE-2026-6732",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2461300",
            "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097",
            "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411"
          ],
          "description": "A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6732",
              "epss": 0.00632,
              "percentile": 0.4666,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6732",
              "cwe": "CWE-843",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libxml2",
              "version": "0:2.9.13-14.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6732",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a840257087cebda4",
        "name": "libxml2",
        "version": "2.9.13-14.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libxml2-2.9.13-14.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-32636",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2023-32636",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.2,
              "exploitabilityScore": 2.6,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2023-32636",
            "epss": 0.0078,
            "percentile": 0.52214,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2023-32636",
            "cwe": "CWE-400",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2023-32636",
            "cwe": "CWE-502",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.35879999999999995
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-32636",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-32636",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://gitlab.gnome.org/GNOME/glib/-/issues/2841",
            "https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835",
            "https://security.netapp.com/advisory/ntap-20231110-0002/"
          ],
          "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-32636",
              "epss": 0.0078,
              "percentile": 0.52214,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2023-32636",
              "cwe": "CWE-400",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2023-32636",
              "cwe": "CWE-502",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-32636",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5773",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5773",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libcurl. Due to a logical error in the connection reuse mechanism for SMB (Server Message Block) transfers, libcurl might reuse an existing SMB connection with a different share than intended. This vulnerability, categorized as CWE-488 (Exposure of Data Element to Wrong Session), could lead to the download of an incorrect file or the upload of a file to an unintended location when an application uses libcurl for SMB transfers.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5773",
            "epss": 0.00618,
            "percentile": 0.46036,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5773",
            "cwe": "CWE-918",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.35534999999999994
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5773",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-5773.html",
            "https://curl.se/docs/CVE-2026-5773.json",
            "https://hackerone.com/reports/3650689",
            "http://www.openwall.com/lists/oss-security/2026/04/29/9"
          ],
          "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5773",
              "epss": 0.00618,
              "percentile": 0.46036,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5773",
              "cwe": "CWE-918",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5773",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5773",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5773",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libcurl. Due to a logical error in the connection reuse mechanism for SMB (Server Message Block) transfers, libcurl might reuse an existing SMB connection with a different share than intended. This vulnerability, categorized as CWE-488 (Exposure of Data Element to Wrong Session), could lead to the download of an incorrect file or the upload of a file to an unintended location when an application uses libcurl for SMB transfers.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5773",
            "epss": 0.00618,
            "percentile": 0.46036,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5773",
            "cwe": "CWE-918",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.35534999999999994
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5773",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-5773.html",
            "https://curl.se/docs/CVE-2026-5773.json",
            "https://hackerone.com/reports/3650689",
            "http://www.openwall.com/lists/oss-security/2026/04/29/9"
          ],
          "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5773",
              "epss": 0.00618,
              "percentile": 0.46036,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5773",
              "cwe": "CWE-918",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5773",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11856",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-11856",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When `libcurl` performs a transfer to an HTTP origin using Digest authentication and then reuses the same connection handle for a subsequent transfer to a different origin, it may incorrectly send the authentication header intended for the first origin to the second. This could lead to unintended information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-11856",
            "epss": 0.00604,
            "percentile": 0.45386,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11856",
            "cwe": "CWE-294",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.3473
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11856",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-11856.html",
            "https://curl.se/docs/CVE-2026-11856.json",
            "https://hackerone.com/reports/3793260"
          ],
          "description": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11856",
              "epss": 0.00604,
              "percentile": 0.45386,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11856",
              "cwe": "CWE-294",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11856",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11856",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-11856",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When `libcurl` performs a transfer to an HTTP origin using Digest authentication and then reuses the same connection handle for a subsequent transfer to a different origin, it may incorrectly send the authentication header intended for the first origin to the second. This could lead to unintended information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-11856",
            "epss": 0.00604,
            "percentile": 0.45386,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11856",
            "cwe": "CWE-294",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.3473
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11856",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-11856.html",
            "https://curl.se/docs/CVE-2026-11856.json",
            "https://hackerone.com/reports/3793260"
          ],
          "description": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11856",
              "epss": 0.00604,
              "percentile": 0.45386,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11856",
              "cwe": "CWE-294",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11856",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-58016",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-58016",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-58016",
            "epss": 0.00445,
            "percentile": 0.36453,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-58016",
            "cwe": "CWE-191",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.68.4-19.el9_8.2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.68.4-19.el9_8.2",
              "date": "2026-07-21",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42089",
            "link": "https://access.redhat.com/errata/RHSA-2026:42089"
          }
        ],
        "risk": 0.33375
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-58016",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-58016",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:42063",
            "https://access.redhat.com/errata/RHSA-2026:42089",
            "https://access.redhat.com/errata/RHSA-2026:42090",
            "https://access.redhat.com/errata/RHSA-2026:44481",
            "https://access.redhat.com/errata/RHSA-2026:46836",
            "https://access.redhat.com/security/cve/CVE-2026-58016",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2492257",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3932"
          ],
          "description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-58016",
              "epss": 0.00445,
              "percentile": 0.36453,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-58016",
              "cwe": "CWE-191",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-58016",
            "versionConstraint": "< 0:2.68.4-19.el9_8.2 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.68.4-19.el9_8.2"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40355",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-40355",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit a NULL pointer dereference vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the termination of the process, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40355",
            "epss": 0.00611,
            "percentile": 0.45653,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40355",
            "cwe": "CWE-476",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:1.21.1-10.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:1.21.1-10.el9_8",
              "date": "2026-05-20",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:19357",
            "link": "https://access.redhat.com/errata/RHSA-2026:19357"
          }
        ],
        "risk": 0.33299500000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40355",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40355",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html",
            "https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f",
            "https://web.mit.edu/kerberos/advisories/",
            "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40355",
              "epss": 0.00611,
              "percentile": 0.45653,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40355",
              "cwe": "CWE-476",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "krb5",
              "version": "1.21.1-8.el9_6"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40355",
            "versionConstraint": "< 0:1.21.1-10.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:1.21.1-10.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "a9ecfba863face9a",
        "name": "krb5-libs",
        "version": "1.21.1-8.el9_6",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:krb5-libs:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5-libs:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5_libs:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5_libs:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/krb5-libs@1.21.1-8.el9_6?arch=x86_64&distro=rhel-9.7&upstream=krb5-1.21.1-8.el9_6.src.rpm",
        "upstreams": [
          {
            "name": "krb5",
            "version": "1.21.1-8.el9_6"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-45186",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-45186",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in libexpat. When processing a specially crafted XML input containing a specific pattern of attributes, the parsing time increases quadratically due to checks for attribute name collisions. This consumes excessive CPU resources and eventually results in a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-45186",
            "epss": 0.00443,
            "percentile": 0.36294,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-45186",
            "cwe": "CWE-407",
            "source": "cve@mitre.org",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-45186",
            "cwe": "CWE-407",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.5.0-6.el9_8.1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.5.0-6.el9_8.1",
              "date": "2026-06-05",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:23230",
            "link": "https://access.redhat.com/errata/RHSA-2026:23230"
          }
        ],
        "risk": 0.33225
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-45186",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-45186",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/libexpat/libexpat/pull/1216",
            "http://www.openwall.com/lists/oss-security/2026/05/11/16",
            "https://access.redhat.com/errata/RHSA-2026:22715",
            "https://access.redhat.com/errata/RHSA-2026:22721",
            "https://access.redhat.com/errata/RHSA-2026:23230",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:27201",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/security/cve/CVE-2026-45186",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2468575",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json"
          ],
          "description": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-45186",
              "epss": 0.00443,
              "percentile": 0.36294,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-45186",
              "cwe": "CWE-407",
              "source": "cve@mitre.org",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-45186",
              "cwe": "CWE-407",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-45186",
            "versionConstraint": "< 0:2.5.0-6.el9_8.1 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.5.0-6.el9_8.1"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40356",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-40356",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit an integer underflow and an out-of-bounds read vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the process terminating, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40356",
            "epss": 0.00604,
            "percentile": 0.45359,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40356",
            "cwe": "CWE-191",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:1.21.1-10.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:1.21.1-10.el9_8",
              "date": "2026-05-20",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:19357",
            "link": "https://access.redhat.com/errata/RHSA-2026:19357"
          }
        ],
        "risk": 0.32918000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40356",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40356",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html",
            "https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f",
            "https://web.mit.edu/kerberos/advisories/"
          ],
          "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40356",
              "epss": 0.00604,
              "percentile": 0.45359,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40356",
              "cwe": "CWE-191",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "krb5",
              "version": "1.21.1-8.el9_6"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40356",
            "versionConstraint": "< 0:1.21.1-10.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:1.21.1-10.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "a9ecfba863face9a",
        "name": "krb5-libs",
        "version": "1.21.1-8.el9_6",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:krb5-libs:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5-libs:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5_libs:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5_libs:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/krb5-libs@1.21.1-8.el9_6?arch=x86_64&distro=rhel-9.7&upstream=krb5-1.21.1-8.el9_6.src.rpm",
        "upstreams": [
          {
            "name": "krb5",
            "version": "1.21.1-8.el9_6"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-3833",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-3833",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-3833",
            "epss": 0.00565,
            "percentile": 0.4357,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-3833",
            "cwe": "CWE-178",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.32487499999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-3833",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-3833",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-3833",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2445763",
            "https://gitlab.com/gnutls/gnutls/-/issues/1803"
          ],
          "description": "A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.4,
                "exploitabilityScore": 2.3,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-3833",
              "epss": 0.00565,
              "percentile": 0.4357,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-3833",
              "cwe": "CWE-178",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-3833",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-51303",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-51303",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in SQLite. A remote attacker can exploit a use-after-free vulnerability in the core parsing component by sending specially crafted SQL queries. This can lead to an application crash, sensitive information disclosure, and potentially allow the attacker to execute arbitrary code on the affected system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 9.8,
              "exploitabilityScore": 3.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-51303",
            "epss": 0.00373,
            "percentile": 0.29974,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-51303",
            "cwe": "CWE-416",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.32264499999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-51303",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-51303",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51303",
            "https://github.com/sqlite/sqlite/blob/master/src/expr.c"
          ],
          "description": "A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an ExprList object via sqlite3ExprListDelete and then subsequently accesses the dangling pointer of the released object. A remote adversary can supply specially crafted SQL queries to trigger this vulnerability during SQL statement parsing. Successful exploitation may result in application crash (denial of service), sensitive memory information leakage, and in some scenarios, arbitrary code execution on the affected host.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-51303",
              "epss": 0.00373,
              "percentile": 0.29974,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-51303",
              "cwe": "CWE-416",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "sqlite",
              "version": "3.34.1-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-51303",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "1bd197aae1b6fd3b",
        "name": "sqlite-libs",
        "version": "3.34.1-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/sqlite-libs@3.34.1-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=sqlite-3.34.1-9.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "sqlite",
            "version": "3.34.1-9.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8924",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-8924",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8924",
            "epss": 0.0056,
            "percentile": 0.43302,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.32199999999999995
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8924",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-8924.html",
            "https://curl.se/docs/CVE-2026-8924.json",
            "https://hackerone.com/reports/3733905"
          ],
          "description": "A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8924",
              "epss": 0.0056,
              "percentile": 0.43302,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8924",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8924",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-8924",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8924",
            "epss": 0.0056,
            "percentile": 0.43302,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.32199999999999995
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8924",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-8924.html",
            "https://curl.se/docs/CVE-2026-8924.json",
            "https://hackerone.com/reports/3733905"
          ],
          "description": "A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8924",
              "epss": 0.0056,
              "percentile": 0.43302,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8924",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-27113",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-27113",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libxml2. This vulnerability allows a NULL pointer dereference, leading to a potential crash or denial of service via a crafted XML pattern.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.1,
              "exploitabilityScore": 1.7,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-27113",
            "epss": 0.01015,
            "percentile": 0.59717,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-27113",
            "cwe": "CWE-476",
            "source": "cve@mitre.org",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2025-27113",
            "cwe": "CWE-476",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.30957499999999993
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-27113",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-27113",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://gitlab.gnome.org/GNOME/libxml2/-/issues/861",
            "http://seclists.org/fulldisclosure/2025/Apr/10",
            "http://seclists.org/fulldisclosure/2025/Apr/11",
            "http://seclists.org/fulldisclosure/2025/Apr/12",
            "http://seclists.org/fulldisclosure/2025/Apr/13",
            "http://seclists.org/fulldisclosure/2025/Apr/4",
            "http://seclists.org/fulldisclosure/2025/Apr/5",
            "http://seclists.org/fulldisclosure/2025/Apr/8",
            "http://seclists.org/fulldisclosure/2025/Apr/9",
            "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html",
            "https://security.netapp.com/advisory/ntap-20250306-0004/"
          ],
          "description": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-27113",
              "epss": 0.01015,
              "percentile": 0.59717,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-27113",
              "cwe": "CWE-476",
              "source": "cve@mitre.org",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2025-27113",
              "cwe": "CWE-476",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libxml2",
              "version": "0:2.9.13-14.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-27113",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a840257087cebda4",
        "name": "libxml2",
        "version": "2.9.13-14.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libxml2-2.9.13-14.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-14512",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-14512",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-14512",
            "epss": 0.00524,
            "percentile": 0.41377,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-14512",
            "cwe": "CWE-190",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.68.4-18.el9_7.2"
          ],
          "state": "fixed"
        },
        "advisories": [
          {
            "id": "RHSA-2026:15971",
            "link": "https://access.redhat.com/errata/RHSA-2026:15971"
          }
        ],
        "risk": 0.30129999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-14512",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-14512",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:15953",
            "https://access.redhat.com/errata/RHSA-2026:15969",
            "https://access.redhat.com/errata/RHSA-2026:15971",
            "https://access.redhat.com/errata/RHSA-2026:19148",
            "https://access.redhat.com/errata/RHSA-2026:19361",
            "https://access.redhat.com/errata/RHSA-2026:19452",
            "https://access.redhat.com/errata/RHSA-2026:19457",
            "https://access.redhat.com/errata/RHSA-2026:19459",
            "https://access.redhat.com/errata/RHSA-2026:19460",
            "https://access.redhat.com/errata/RHSA-2026:19523",
            "https://access.redhat.com/errata/RHSA-2026:19524",
            "https://access.redhat.com/errata/RHSA-2026:19565",
            "https://access.redhat.com/errata/RHSA-2026:19567",
            "https://access.redhat.com/errata/RHSA-2026:21275",
            "https://access.redhat.com/errata/RHSA-2026:22634",
            "https://access.redhat.com/errata/RHSA-2026:25096",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:7461",
            "https://access.redhat.com/security/cve/CVE-2025-14512",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2421339",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3845"
          ],
          "description": "A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-14512",
              "epss": 0.00524,
              "percentile": 0.41377,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-14512",
              "cwe": "CWE-190",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-14512",
            "versionConstraint": "< 0:2.68.4-18.el9_7.2 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.68.4-18.el9_7.2"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6429",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-6429",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libcurl. When configured to use a .netrc file for credentials and follow HTTP redirects, libcurl can inadvertently send the password from the initial connection to the redirected host. This sensitive information disclosure occurs when both the original and redirect URLs use clear text HTTP, are performed over the same HTTP proxy, and the same connection is reused. This vulnerability, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), could allow an attacker to obtain user credentials.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6429",
            "epss": 0.00519,
            "percentile": 0.41113,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.298425
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6429",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-6429.html",
            "https://curl.se/docs/CVE-2026-6429.json",
            "https://hackerone.com/reports/3677759"
          ],
          "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6429",
              "epss": 0.00519,
              "percentile": 0.41113,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6429",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6429",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-6429",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libcurl. When configured to use a .netrc file for credentials and follow HTTP redirects, libcurl can inadvertently send the password from the initial connection to the redirected host. This sensitive information disclosure occurs when both the original and redirect URLs use clear text HTTP, are performed over the same HTTP proxy, and the same connection is reused. This vulnerability, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), could allow an attacker to obtain user credentials.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6429",
            "epss": 0.00519,
            "percentile": 0.41113,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.298425
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6429",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-6429.html",
            "https://curl.se/docs/CVE-2026-6429.json",
            "https://hackerone.com/reports/3677759"
          ],
          "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6429",
              "epss": 0.00519,
              "percentile": 0.41113,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6429",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-51297",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-51297",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in sqlite. This use-after-free vulnerability in the JSON parsing logic allows remote attackers to craft malicious JSON payloads. This can trigger memory deallocation followed by illegal memory access, potentially leading to arbitrary code execution, sensitive information leakage, or denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 9.8,
              "exploitabilityScore": 3.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-51297",
            "epss": 0.00344,
            "percentile": 0.26984,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-51297",
            "cwe": "CWE-416",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.29756
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-51297",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-51297",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51297",
            "https://github.com/sqlite/sqlite/blob/master/src/json.c"
          ],
          "description": "sqlite 3.41 has a use-after-free vulnerability in the JSON parsing logic. Remote adversaries can craft malicious JSON payload to trigger memory free followed by illegal memory access, which may lead to arbitrary code execution, sensitive information leakage and service denial.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-51297",
              "epss": 0.00344,
              "percentile": 0.26984,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-51297",
              "cwe": "CWE-416",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "sqlite",
              "version": "3.34.1-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-51297",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "1bd197aae1b6fd3b",
        "name": "sqlite-libs",
        "version": "3.34.1-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/sqlite-libs@3.34.1-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=sqlite-3.34.1-9.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "sqlite",
            "version": "3.34.1-9.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42011",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42011",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 7.4,
              "exploitabilityScore": 2.3,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42011",
            "epss": 0.00475,
            "percentile": 0.38466,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42011",
            "cwe": "CWE-295",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.2945
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42011",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42011",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:40762",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-42011",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467437",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-6"
          ],
          "description": "A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.4,
                "exploitabilityScore": 2.3,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42011",
              "epss": 0.00475,
              "percentile": 0.38466,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42011",
              "cwe": "CWE-295",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42011",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-51304",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-51304",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in sqlite. A remote attacker can exploit a use-after-free vulnerability in the ORDER BY clause parsing routine by crafting a malicious SQL statement. This can lead to an application crash, sensitive information disclosure, and in some cases, arbitrary code execution, allowing the attacker to run their own commands on the affected system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 9.8,
              "exploitabilityScore": 3.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-51304",
            "epss": 0.0034,
            "percentile": 0.26612,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-51304",
            "cwe": "CWE-416",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.2941
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-51304",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-51304",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51304",
            "https://github.com/sqlite/sqlite/blob/master/src/expr.c"
          ],
          "description": "sqlite 3.41 has a use-after-free (UAF) vulnerability in the ORDER BY clause parsing routine. The affected code first releases the memory of an ExprList object via sqlite3ExprListDelete(), then attempts to access the nExpr member of the already freed object. This dangling pointer access causes invalid memory read operations. By constructing a malicious SQL statement containing an ORDER BY clause with a large number of items, a remote adversary can trigger this vulnerability. Successful exploitation can result in application crash (denial of service), leakage of sensitive memory contents, and under certain memory layout conditions, arbitrary code execution on the affected system.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-51304",
              "epss": 0.0034,
              "percentile": 0.26612,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-51304",
              "cwe": "CWE-416",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "sqlite",
              "version": "3.34.1-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-51304",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "1bd197aae1b6fd3b",
        "name": "sqlite-libs",
        "version": "3.34.1-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/sqlite-libs@3.34.1-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=sqlite-3.34.1-9.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "sqlite",
            "version": "3.34.1-9.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-14524",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-14524",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in curl. When an OAuth2 (Open Authorization) bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a different scheme like IMAP, LDAP, POP3, or SMTP, curl might incorrectly pass the bearer token to the new target host. This could lead to information disclosure, where sensitive authentication tokens are exposed to unintended recipients.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-14524",
            "epss": 0.00611,
            "percentile": 0.45702,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-14524",
            "cwe": "CWE-601",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.290225
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-14524",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-14524.html",
            "https://curl.se/docs/CVE-2025-14524.json",
            "https://hackerone.com/reports/3459417",
            "http://www.openwall.com/lists/oss-security/2026/01/07/4"
          ],
          "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-14524",
              "epss": 0.00611,
              "percentile": 0.45702,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-14524",
              "cwe": "CWE-601",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-14524",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-14524",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-14524",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in curl. When an OAuth2 (Open Authorization) bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a different scheme like IMAP, LDAP, POP3, or SMTP, curl might incorrectly pass the bearer token to the new target host. This could lead to information disclosure, where sensitive authentication tokens are exposed to unintended recipients.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-14524",
            "epss": 0.00611,
            "percentile": 0.45702,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-14524",
            "cwe": "CWE-601",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.290225
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-14524",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-14524.html",
            "https://curl.se/docs/CVE-2025-14524.json",
            "https://hackerone.com/reports/3459417",
            "http://www.openwall.com/lists/oss-security/2026/01/07/4"
          ],
          "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-14524",
              "epss": 0.00611,
              "percentile": 0.45702,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-14524",
              "cwe": "CWE-601",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-14524",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42013",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42013",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "metrics": {
              "baseScore": 8.2,
              "exploitabilityScore": 3.9,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42013",
            "epss": 0.00423,
            "percentile": 0.34714,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42013",
            "cwe": "CWE-295",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.27918
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42013",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42013",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:40762",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-42013",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467448",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-8"
          ],
          "description": "A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
              "metrics": {
                "baseScore": 8.2,
                "exploitabilityScore": 3.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42013",
              "epss": 0.00423,
              "percentile": 0.34714,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42013",
              "cwe": "CWE-295",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42013",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42768",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42768",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL's CMS_decrypt() and PKCS7_decrypt() functions. This vulnerability, a Bleichenbacher-style oracle, could allow a remote attacker to decrypt or sign messages using the victim's private RSA key. Exploitation requires the attacker to provide specially crafted CMS or S/MIME messages and observe the application's error codes or decryption output. While the attack is technically possible, the specific conditions required make it unlikely to be exploited in typical deployments.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 6.3,
              "exploitabilityScore": 1.1,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42768",
            "epss": 0.0058,
            "percentile": 0.44294,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42768",
            "cwe": "CWE-514",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.2697
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42768",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42768",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://github.com/openssl/openssl/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f",
            "https://github.com/openssl/openssl/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d",
            "https://github.com/openssl/openssl/commit/dd68364107a58841c0a2546812518b65d3a23abd",
            "https://github.com/openssl/openssl/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\n\nImpact summary: The Bleichenbacher-style attack allows an attacker to use the\nvictim's vulnerable application as a way to decrypt or sign messages with the\nvictim's private RSA key.\n\nThe attack is possible in 2 variants.\n\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over every\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\n\nAn attacker who authors a message with two KTRI entries — the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\n\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts any\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under\nit.\n\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\n\nAn attacker who authors a message and is able to compare both error code and\nthe result of the decryption, can mount a Bleichenbacher oracle.\n\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\n\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\n\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\n\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42768",
              "epss": 0.0058,
              "percentile": 0.44294,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42768",
              "cwe": "CWE-514",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42768",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42768",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42768",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL's CMS_decrypt() and PKCS7_decrypt() functions. This vulnerability, a Bleichenbacher-style oracle, could allow a remote attacker to decrypt or sign messages using the victim's private RSA key. Exploitation requires the attacker to provide specially crafted CMS or S/MIME messages and observe the application's error codes or decryption output. While the attack is technically possible, the specific conditions required make it unlikely to be exploited in typical deployments.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 6.3,
              "exploitabilityScore": 1.1,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42768",
            "epss": 0.0058,
            "percentile": 0.44294,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42768",
            "cwe": "CWE-514",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.2697
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42768",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42768",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://github.com/openssl/openssl/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f",
            "https://github.com/openssl/openssl/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d",
            "https://github.com/openssl/openssl/commit/dd68364107a58841c0a2546812518b65d3a23abd",
            "https://github.com/openssl/openssl/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\n\nImpact summary: The Bleichenbacher-style attack allows an attacker to use the\nvictim's vulnerable application as a way to decrypt or sign messages with the\nvictim's private RSA key.\n\nThe attack is possible in 2 variants.\n\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over every\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\n\nAn attacker who authors a message with two KTRI entries — the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\n\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts any\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under\nit.\n\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\n\nAn attacker who authors a message and is able to compare both error code and\nthe result of the decryption, can mount a Bleichenbacher oracle.\n\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\n\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\n\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\n\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42768",
              "epss": 0.0058,
              "percentile": 0.44294,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42768",
              "cwe": "CWE-514",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42768",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-7383",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-7383",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.8
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-7383",
            "epss": 0.0063,
            "percentile": 0.46544,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-7383",
            "cwe": "CWE-787",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.26775000000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-7383",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-7383",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6",
            "https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74",
            "https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974",
            "https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083",
            "https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.3,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-7383",
              "epss": 0.0063,
              "percentile": 0.46544,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-7383",
              "cwe": "CWE-787",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-7383",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-7383",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-7383",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.8
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-7383",
            "epss": 0.0063,
            "percentile": 0.46544,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-7383",
            "cwe": "CWE-787",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.26775000000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-7383",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-7383",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6",
            "https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74",
            "https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974",
            "https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083",
            "https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.3,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-7383",
              "epss": 0.0063,
              "percentile": 0.46544,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-7383",
              "cwe": "CWE-787",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-7383",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-9076",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-9076",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-9076",
            "epss": 0.00589,
            "percentile": 0.44671,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-9076",
            "cwe": "CWE-125",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.2621050000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-9076",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-9076",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb",
            "https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0",
            "https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98",
            "https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26",
            "https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-9076",
              "epss": 0.00589,
              "percentile": 0.44671,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-9076",
              "cwe": "CWE-125",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-9076",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-9076",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-9076",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-9076",
            "epss": 0.00589,
            "percentile": 0.44671,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-9076",
            "cwe": "CWE-125",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.2621050000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-9076",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-9076",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb",
            "https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0",
            "https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98",
            "https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26",
            "https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-9076",
              "epss": 0.00589,
              "percentile": 0.44671,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-9076",
              "cwe": "CWE-125",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-9076",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-15079",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-15079",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in curl. When performing SSH-based transfers using SCP or SFTP, libcurl could mistakenly connect to hosts not listed in the user-specified knownhosts file. This occurs if the host is present in the libssh global knownhosts file, effectively bypassing the intended host verification. This could allow a remote attacker to connect to an untrusted host, potentially leading to information disclosure or man-in-the-middle attacks.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-15079",
            "epss": 0.00457,
            "percentile": 0.37266,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-15079",
            "cwe": "CWE-297",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.25363499999999994
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-15079",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-15079.html",
            "https://curl.se/docs/CVE-2025-15079.json",
            "https://hackerone.com/reports/3477116",
            "http://www.openwall.com/lists/oss-security/2026/01/07/6"
          ],
          "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-15079",
              "epss": 0.00457,
              "percentile": 0.37266,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-15079",
              "cwe": "CWE-297",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-15079",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-15079",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-15079",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in curl. When performing SSH-based transfers using SCP or SFTP, libcurl could mistakenly connect to hosts not listed in the user-specified knownhosts file. This occurs if the host is present in the libssh global knownhosts file, effectively bypassing the intended host verification. This could allow a remote attacker to connect to an untrusted host, potentially leading to information disclosure or man-in-the-middle attacks.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-15079",
            "epss": 0.00457,
            "percentile": 0.37266,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-15079",
            "cwe": "CWE-297",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.25363499999999994
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-15079",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-15079.html",
            "https://curl.se/docs/CVE-2025-15079.json",
            "https://hackerone.com/reports/3477116",
            "http://www.openwall.com/lists/oss-security/2026/01/07/6"
          ],
          "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-15079",
              "epss": 0.00457,
              "percentile": 0.37266,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-15079",
              "cwe": "CWE-297",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-15079",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-58015",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-58015",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-58015",
            "epss": 0.00463,
            "percentile": 0.37708,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-58015",
            "cwe": "CWE-22",
            "source": "secalert@redhat.com",
            "type": "Primary"
          },
          {
            "cve": "CVE-2026-58015",
            "cwe": "CWE-22",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.25233500000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-58015",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-58015",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-58015",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2492256",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3931"
          ],
          "description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-58015",
              "epss": 0.00463,
              "percentile": 0.37708,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-58015",
              "cwe": "CWE-22",
              "source": "secalert@redhat.com",
              "type": "Primary"
            },
            {
              "cve": "CVE-2026-58015",
              "cwe": "CWE-22",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-58015",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5450",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5450",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H",
            "metrics": {
              "baseScore": 5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5450",
            "epss": 0.00502,
            "percentile": 0.40088,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5450",
            "cwe": "CWE-122",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-5450",
            "cwe": "CWE-787",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-272.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-272.el9_8",
              "date": "2026-06-30",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:33226",
            "link": "https://access.redhat.com/errata/RHSA-2026:33226"
          }
        ],
        "risk": 0.251
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5450",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5450",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5450",
              "epss": 0.00502,
              "percentile": 0.40088,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5450",
              "cwe": "CWE-122",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-5450",
              "cwe": "CWE-787",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "0:2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5450",
            "versionConstraint": "< 0:2.34-272.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-272.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "d41f8063e44e2263",
        "name": "glibc",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5450",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5450",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H",
            "metrics": {
              "baseScore": 5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5450",
            "epss": 0.00502,
            "percentile": 0.40088,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5450",
            "cwe": "CWE-122",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-5450",
            "cwe": "CWE-787",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-272.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-272.el9_8",
              "date": "2026-06-30",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:33226",
            "link": "https://access.redhat.com/errata/RHSA-2026:33226"
          }
        ],
        "risk": 0.251
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5450",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5450",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5450",
              "epss": 0.00502,
              "percentile": 0.40088,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5450",
              "cwe": "CWE-122",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-5450",
              "cwe": "CWE-787",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5450",
            "versionConstraint": "< 0:2.34-272.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-272.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "1135b72e9fa314da",
        "name": "glibc-common",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-common@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5450",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5450",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H",
            "metrics": {
              "baseScore": 5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5450",
            "epss": 0.00502,
            "percentile": 0.40088,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5450",
            "cwe": "CWE-122",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-5450",
            "cwe": "CWE-787",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-272.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-272.el9_8",
              "date": "2026-06-30",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:33226",
            "link": "https://access.redhat.com/errata/RHSA-2026:33226"
          }
        ],
        "risk": 0.251
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5450",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5450",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5450",
              "epss": 0.00502,
              "percentile": 0.40088,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5450",
              "cwe": "CWE-122",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-5450",
              "cwe": "CWE-787",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5450",
            "versionConstraint": "< 0:2.34-272.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-272.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "81f30677c0ddeeec",
        "name": "glibc-minimal-langpack",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-2673",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-2673",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A key group selection preference flaw has been discovered in OpenSSL. An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the \"DEFAULT\" keyword. A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-2673",
            "epss": 0.00435,
            "percentile": 0.35685,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-2673",
            "cwe": "CWE-757",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.25012499999999993
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-2673",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-2673",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f",
            "https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34",
            "https://openssl-library.org/news/secadv/20260313.txt",
            "http://www.openwall.com/lists/oss-security/2026/03/13/3",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected\npreferred key exchange group when its key exchange group configuration includes\nthe default by using the 'DEFAULT' keyword.\n\nImpact summary: A less preferred key exchange may be used even when a more\npreferred group is supported by both client and server, if the group\nwas not included among the client's initial predicated keyshares.\nThis will sometimes be the case with the new hybrid post-quantum groups,\nif the client chooses to defer their use until specifically requested by\nthe server.\n\nIf an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to\ninterpolate the built-in default group list into its own configuration, perhaps\nadding or removing specific elements, then an implementation defect causes the\n'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups\nwere treated as a single sufficiently secure 'tuple', with the server not\nsending a Hello Retry Request (HRR) even when a group in a more preferred tuple\nwas mutually supported.\n\nAs a result, the client and server might fail to negotiate a mutually supported\npost-quantum key agreement group, such as 'X25519MLKEM768', if the client's\nconfiguration results in only 'classical' groups (such as 'X25519' being the\nonly ones in the client's initial keyshare prediction).\n\nOpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS\n1.3 key agreement group on TLS servers.  The old syntax had a single 'flat'\nlist of groups, and treated all the supported groups as sufficiently secure.\nIf any of the keyshares predicted by the client were supported by the server\nthe most preferred among these was selected, even if other groups supported by\nthe client, but not included in the list of predicted keyshares would have been\nmore preferred, if included.\n\nThe new syntax partitions the groups into distinct 'tuples' of roughly\nequivalent security.  Within each tuple the most preferred group included among\nthe client's predicted keyshares is chosen, but if the client supports a group\nfrom a more preferred tuple, but did not predict any corresponding keyshares,\nthe server will ask the client to retry the ClientHello (by issuing a Hello\nRetry Request or HRR) with the most preferred mutually supported group.\n\nThe above works as expected when the server's configuration uses the built-in\ndefault group list, or explicitly defines its own list by directly defining the\nvarious desired groups and group 'tuples'.\n\nNo OpenSSL FIPS modules are affected by this issue, the code in question lies\noutside the FIPS boundary.\n\nOpenSSL 3.6 and 3.5 are vulnerable to this issue.\n\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.\n\nOpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-2673",
              "epss": 0.00435,
              "percentile": 0.35685,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-2673",
              "cwe": "CWE-757",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-2673",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-2673",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-2673",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A key group selection preference flaw has been discovered in OpenSSL. An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the \"DEFAULT\" keyword. A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-2673",
            "epss": 0.00435,
            "percentile": 0.35685,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-2673",
            "cwe": "CWE-757",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.25012499999999993
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-2673",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-2673",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f",
            "https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34",
            "https://openssl-library.org/news/secadv/20260313.txt",
            "http://www.openwall.com/lists/oss-security/2026/03/13/3",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected\npreferred key exchange group when its key exchange group configuration includes\nthe default by using the 'DEFAULT' keyword.\n\nImpact summary: A less preferred key exchange may be used even when a more\npreferred group is supported by both client and server, if the group\nwas not included among the client's initial predicated keyshares.\nThis will sometimes be the case with the new hybrid post-quantum groups,\nif the client chooses to defer their use until specifically requested by\nthe server.\n\nIf an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to\ninterpolate the built-in default group list into its own configuration, perhaps\nadding or removing specific elements, then an implementation defect causes the\n'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups\nwere treated as a single sufficiently secure 'tuple', with the server not\nsending a Hello Retry Request (HRR) even when a group in a more preferred tuple\nwas mutually supported.\n\nAs a result, the client and server might fail to negotiate a mutually supported\npost-quantum key agreement group, such as 'X25519MLKEM768', if the client's\nconfiguration results in only 'classical' groups (such as 'X25519' being the\nonly ones in the client's initial keyshare prediction).\n\nOpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS\n1.3 key agreement group on TLS servers.  The old syntax had a single 'flat'\nlist of groups, and treated all the supported groups as sufficiently secure.\nIf any of the keyshares predicted by the client were supported by the server\nthe most preferred among these was selected, even if other groups supported by\nthe client, but not included in the list of predicted keyshares would have been\nmore preferred, if included.\n\nThe new syntax partitions the groups into distinct 'tuples' of roughly\nequivalent security.  Within each tuple the most preferred group included among\nthe client's predicted keyshares is chosen, but if the client supports a group\nfrom a more preferred tuple, but did not predict any corresponding keyshares,\nthe server will ask the client to retry the ClientHello (by issuing a Hello\nRetry Request or HRR) with the most preferred mutually supported group.\n\nThe above works as expected when the server's configuration uses the built-in\ndefault group list, or explicitly defines its own list by directly defining the\nvarious desired groups and group 'tuples'.\n\nNo OpenSSL FIPS modules are affected by this issue, the code in question lies\noutside the FIPS boundary.\n\nOpenSSL 3.6 and 3.5 are vulnerable to this issue.\n\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.\n\nOpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-2673",
              "epss": 0.00435,
              "percentile": 0.35685,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-2673",
              "cwe": "CWE-757",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl-fips-provider",
              "version": "0:3.0.7-8.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-2673",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "4f0f0ad93452efa2",
        "name": "openssl-fips-provider",
        "version": "3.0.7-8.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "ASL 2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-fips-provider:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips-provider:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-fips-provider:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_fips_provider:3.0.7-8.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-fips-provider@3.0.7-8.el9?arch=x86_64&distro=rhel-9.7&upstream=openssl-fips-provider-3.0.7-8.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-2673",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-2673",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A key group selection preference flaw has been discovered in OpenSSL. An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the \"DEFAULT\" keyword. A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-2673",
            "epss": 0.00435,
            "percentile": 0.35685,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-2673",
            "cwe": "CWE-757",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.25012499999999993
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-2673",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-2673",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f",
            "https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34",
            "https://openssl-library.org/news/secadv/20260313.txt",
            "http://www.openwall.com/lists/oss-security/2026/03/13/3",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected\npreferred key exchange group when its key exchange group configuration includes\nthe default by using the 'DEFAULT' keyword.\n\nImpact summary: A less preferred key exchange may be used even when a more\npreferred group is supported by both client and server, if the group\nwas not included among the client's initial predicated keyshares.\nThis will sometimes be the case with the new hybrid post-quantum groups,\nif the client chooses to defer their use until specifically requested by\nthe server.\n\nIf an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to\ninterpolate the built-in default group list into its own configuration, perhaps\nadding or removing specific elements, then an implementation defect causes the\n'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups\nwere treated as a single sufficiently secure 'tuple', with the server not\nsending a Hello Retry Request (HRR) even when a group in a more preferred tuple\nwas mutually supported.\n\nAs a result, the client and server might fail to negotiate a mutually supported\npost-quantum key agreement group, such as 'X25519MLKEM768', if the client's\nconfiguration results in only 'classical' groups (such as 'X25519' being the\nonly ones in the client's initial keyshare prediction).\n\nOpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS\n1.3 key agreement group on TLS servers.  The old syntax had a single 'flat'\nlist of groups, and treated all the supported groups as sufficiently secure.\nIf any of the keyshares predicted by the client were supported by the server\nthe most preferred among these was selected, even if other groups supported by\nthe client, but not included in the list of predicted keyshares would have been\nmore preferred, if included.\n\nThe new syntax partitions the groups into distinct 'tuples' of roughly\nequivalent security.  Within each tuple the most preferred group included among\nthe client's predicted keyshares is chosen, but if the client supports a group\nfrom a more preferred tuple, but did not predict any corresponding keyshares,\nthe server will ask the client to retry the ClientHello (by issuing a Hello\nRetry Request or HRR) with the most preferred mutually supported group.\n\nThe above works as expected when the server's configuration uses the built-in\ndefault group list, or explicitly defines its own list by directly defining the\nvarious desired groups and group 'tuples'.\n\nNo OpenSSL FIPS modules are affected by this issue, the code in question lies\noutside the FIPS boundary.\n\nOpenSSL 3.6 and 3.5 are vulnerable to this issue.\n\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.\n\nOpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-2673",
              "epss": 0.00435,
              "percentile": 0.35685,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-2673",
              "cwe": "CWE-757",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl-fips-provider",
              "version": "3.0.7-8.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-2673",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "039e508ce9d5da38",
        "name": "openssl-fips-provider-so",
        "version": "3.0.7-8.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "ASL 2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-fips-provider-so:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips-provider-so:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider_so:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider_so:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips-provider:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips-provider:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips_provider:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-fips:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_fips:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-fips-provider-so:3.0.7-8.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_fips_provider_so:3.0.7-8.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-8.el9?arch=x86_64&distro=rhel-9.7&upstream=openssl-fips-provider-3.0.7-8.el9.src.rpm",
        "upstreams": [
          {
            "name": "openssl-fips-provider",
            "version": "3.0.7-8.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-2673",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-2673",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A key group selection preference flaw has been discovered in OpenSSL. An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the \"DEFAULT\" keyword. A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-2673",
            "epss": 0.00435,
            "percentile": 0.35685,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-2673",
            "cwe": "CWE-757",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.25012499999999993
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-2673",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-2673",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f",
            "https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34",
            "https://openssl-library.org/news/secadv/20260313.txt",
            "http://www.openwall.com/lists/oss-security/2026/03/13/3",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected\npreferred key exchange group when its key exchange group configuration includes\nthe default by using the 'DEFAULT' keyword.\n\nImpact summary: A less preferred key exchange may be used even when a more\npreferred group is supported by both client and server, if the group\nwas not included among the client's initial predicated keyshares.\nThis will sometimes be the case with the new hybrid post-quantum groups,\nif the client chooses to defer their use until specifically requested by\nthe server.\n\nIf an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to\ninterpolate the built-in default group list into its own configuration, perhaps\nadding or removing specific elements, then an implementation defect causes the\n'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups\nwere treated as a single sufficiently secure 'tuple', with the server not\nsending a Hello Retry Request (HRR) even when a group in a more preferred tuple\nwas mutually supported.\n\nAs a result, the client and server might fail to negotiate a mutually supported\npost-quantum key agreement group, such as 'X25519MLKEM768', if the client's\nconfiguration results in only 'classical' groups (such as 'X25519' being the\nonly ones in the client's initial keyshare prediction).\n\nOpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS\n1.3 key agreement group on TLS servers.  The old syntax had a single 'flat'\nlist of groups, and treated all the supported groups as sufficiently secure.\nIf any of the keyshares predicted by the client were supported by the server\nthe most preferred among these was selected, even if other groups supported by\nthe client, but not included in the list of predicted keyshares would have been\nmore preferred, if included.\n\nThe new syntax partitions the groups into distinct 'tuples' of roughly\nequivalent security.  Within each tuple the most preferred group included among\nthe client's predicted keyshares is chosen, but if the client supports a group\nfrom a more preferred tuple, but did not predict any corresponding keyshares,\nthe server will ask the client to retry the ClientHello (by issuing a Hello\nRetry Request or HRR) with the most preferred mutually supported group.\n\nThe above works as expected when the server's configuration uses the built-in\ndefault group list, or explicitly defines its own list by directly defining the\nvarious desired groups and group 'tuples'.\n\nNo OpenSSL FIPS modules are affected by this issue, the code in question lies\noutside the FIPS boundary.\n\nOpenSSL 3.6 and 3.5 are vulnerable to this issue.\n\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.\n\nOpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-2673",
              "epss": 0.00435,
              "percentile": 0.35685,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-2673",
              "cwe": "CWE-757",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-2673",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2021-46195",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2021-46195",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was discovered in the GNU libiberty library within the demangle_path() function in rust-demangle.c, as distributed in the GNU Compiler Collection (GCC). This flaw allows a crafted symbol to cause stack memory to be exhausted, leading to a crash.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.3,
              "exploitabilityScore": 1.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2021-46195",
            "epss": 0.00779,
            "percentile": 0.52171,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2021-46195",
            "cwe": "CWE-674",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.24538499999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2021-46195",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2021-46195",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=103841"
          ],
          "description": "GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 8.6,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2021-46195",
              "epss": 0.00779,
              "percentile": 0.52171,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2021-46195",
              "cwe": "CWE-674",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gcc",
              "version": "11.5.0-11.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2021-46195",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "06e2c48d975ea1da",
        "name": "libgcc",
        "version": "11.5.0-11.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libgcc:libgcc:11.5.0-11.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libgcc:11.5.0-11.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libgcc@11.5.0-11.el9?arch=x86_64&distro=rhel-9.7&upstream=gcc-11.5.0-11.el9.src.rpm",
        "upstreams": [
          {
            "name": "gcc",
            "version": "11.5.0-11.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2021-46195",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2021-46195",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was discovered in the GNU libiberty library within the demangle_path() function in rust-demangle.c, as distributed in the GNU Compiler Collection (GCC). This flaw allows a crafted symbol to cause stack memory to be exhausted, leading to a crash.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.3,
              "exploitabilityScore": 1.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2021-46195",
            "epss": 0.00779,
            "percentile": 0.52171,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2021-46195",
            "cwe": "CWE-674",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.24538499999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2021-46195",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2021-46195",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=103841"
          ],
          "description": "GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 8.6,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2021-46195",
              "epss": 0.00779,
              "percentile": 0.52171,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2021-46195",
              "cwe": "CWE-674",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gcc",
              "version": "11.5.0-11.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2021-46195",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "e66b7275c6659e9c",
        "name": "libstdc++",
        "version": "11.5.0-11.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.5.0-11.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libstdc\\+\\+:11.5.0-11.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-11.el9?arch=x86_64&distro=rhel-9.7&upstream=gcc-11.5.0-11.el9.src.rpm",
        "upstreams": [
          {
            "name": "gcc",
            "version": "11.5.0-11.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-7168",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-7168",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authentication and then reuses the same handle for a second transfer with a different proxy host, libcurl incorrectly sends the `Proxy-Authorization` header intended for the first proxy to the second proxy. This could lead to the disclosure of sensitive authentication information to an unintended proxy, potentially allowing an attacker to gain unauthorized access or impersonate the user.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-7168",
            "epss": 0.00471,
            "percentile": 0.38175,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-7168",
            "cwe": "CWE-294",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.242565
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-7168",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-7168.html",
            "https://curl.se/docs/CVE-2026-7168.json",
            "https://hackerone.com/reports/3697719",
            "http://www.openwall.com/lists/oss-security/2026/04/29/14"
          ],
          "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-7168",
              "epss": 0.00471,
              "percentile": 0.38175,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-7168",
              "cwe": "CWE-294",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-7168",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-7168",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-7168",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authentication and then reuses the same handle for a second transfer with a different proxy host, libcurl incorrectly sends the `Proxy-Authorization` header intended for the first proxy to the second proxy. This could lead to the disclosure of sensitive authentication information to an unintended proxy, potentially allowing an attacker to gain unauthorized access or impersonate the user.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-7168",
            "epss": 0.00471,
            "percentile": 0.38175,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-7168",
            "cwe": "CWE-294",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.242565
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-7168",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-7168.html",
            "https://curl.se/docs/CVE-2026-7168.json",
            "https://hackerone.com/reports/3697719",
            "http://www.openwall.com/lists/oss-security/2026/04/29/14"
          ],
          "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-7168",
              "epss": 0.00471,
              "percentile": 0.38175,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-7168",
              "cwe": "CWE-294",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-7168",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-9547",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-9547",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in curl. When a libcurl-based application uses SCP:// or SFTP:// for transfers and employs the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. This occurs if the server's host key type differs from the one stored in the known_hosts file. The callback mechanism fails to enforce the host key restriction, enabling a connection to an untrusted server and risking a man-in-the-middle attack.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 7.4,
              "exploitabilityScore": 2.3,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-9547",
            "epss": 0.00325,
            "percentile": 0.24979,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-9547",
            "cwe": "NVD-CWE-Other",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.24212499999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-9547",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-9547",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-9547.html",
            "https://curl.se/docs/CVE-2026-9547.json",
            "https://hackerone.com/reports/3751712"
          ],
          "description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.4,
                "exploitabilityScore": 2.3,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-9547",
              "epss": 0.00325,
              "percentile": 0.24979,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-9547",
              "cwe": "NVD-CWE-Other",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-9547",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-9547",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-9547",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in curl. When a libcurl-based application uses SCP:// or SFTP:// for transfers and employs the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. This occurs if the server's host key type differs from the one stored in the known_hosts file. The callback mechanism fails to enforce the host key restriction, enabling a connection to an untrusted server and risking a man-in-the-middle attack.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 7.4,
              "exploitabilityScore": 2.3,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-9547",
            "epss": 0.00325,
            "percentile": 0.24979,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-9547",
            "cwe": "NVD-CWE-Other",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.24212499999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-9547",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-9547",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-9547.html",
            "https://curl.se/docs/CVE-2026-9547.json",
            "https://hackerone.com/reports/3751712"
          ],
          "description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.4,
                "exploitabilityScore": 2.3,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-9547",
              "epss": 0.00325,
              "percentile": 0.24979,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-9547",
              "cwe": "NVD-CWE-Other",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-9547",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-3832",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-3832",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-3832",
            "epss": 0.0072,
            "percentile": 0.50166,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-3832",
            "cwe": "CWE-179",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.24119999999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-3832",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-3832",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/security/cve/CVE-2026-3832",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2445762",
            "https://gitlab.com/gnutls/gnutls/-/issues/1801"
          ],
          "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-3832",
              "epss": 0.0072,
              "percentile": 0.50166,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-3832",
              "cwe": "CWE-179",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-3832",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8286",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-8286",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8286",
            "epss": 0.00309,
            "percentile": 0.23281,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-8286",
            "cwe": "CWE-295",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.24101999999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8286",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8286",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-8286.html",
            "https://curl.se/docs/CVE-2026-8286.json",
            "https://hackerone.com/reports/3718195"
          ],
          "description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8286",
              "epss": 0.00309,
              "percentile": 0.23281,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-8286",
              "cwe": "CWE-295",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8286",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8286",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-8286",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8286",
            "epss": 0.00309,
            "percentile": 0.23281,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-8286",
            "cwe": "CWE-295",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.24101999999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8286",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8286",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-8286.html",
            "https://curl.se/docs/CVE-2026-8286.json",
            "https://hackerone.com/reports/3718195"
          ],
          "description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8286",
              "epss": 0.00309,
              "percentile": 0.23281,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-8286",
              "cwe": "CWE-295",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8286",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5545",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5545",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5545",
            "epss": 0.00414,
            "percentile": 0.33937,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5545",
            "cwe": "CWE-613",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.23804999999999993
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5545",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-5545.html",
            "https://curl.se/docs/CVE-2026-5545.json",
            "https://hackerone.com/reports/3642555"
          ],
          "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.3,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.3,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5545",
              "epss": 0.00414,
              "percentile": 0.33937,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5545",
              "cwe": "CWE-613",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5545",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5545",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5545",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5545",
            "epss": 0.00414,
            "percentile": 0.33937,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5545",
            "cwe": "CWE-613",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.23804999999999993
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5545",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-5545.html",
            "https://curl.se/docs/CVE-2026-5545.json",
            "https://hackerone.com/reports/3642555"
          ],
          "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.3,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.3,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5545",
              "epss": 0.00414,
              "percentile": 0.33937,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5545",
              "cwe": "CWE-613",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5545",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-51302",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-51302",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Critical",
        "urls": [],
        "description": "A flaw was found in SQLite. A use-after-free vulnerability in the expression evaluation logic, specifically within the sqlite3ReleaseTempReg and exprComputeOperands functions, allows a remote attacker to exploit the system. By supplying a malicious SQL statement, an attacker can cause a denial of service, leak sensitive information, or potentially execute arbitrary code.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 10,
              "exploitabilityScore": 3.9,
              "impactScore": 6.1
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-51302",
            "epss": 0.00245,
            "percentile": 0.15828,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-51302",
            "cwe": "CWE-416",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.23274999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-51302",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-51302",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51302",
            "https://github.com/sqlite/sqlite/blob/master/src/expr.c"
          ],
          "description": "SQLite 3.41 has a use-after-free vulnerability exists in the expression evaluation logic. The sqlite3ReleaseTempReg function improperly releases temporary register resources, and the subsequent exprComputeOperands function continues to access the already freed register memory. By supplying a malicious SQL statement, a remote attacker can exploit this flaw to cause denial of service, leak sensitive information, or potentially execute arbitrary code on the affected system.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-51302",
              "epss": 0.00245,
              "percentile": 0.15828,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-51302",
              "cwe": "CWE-416",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "sqlite",
              "version": "3.34.1-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-51302",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "1bd197aae1b6fd3b",
        "name": "sqlite-libs",
        "version": "3.34.1-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/sqlite-libs@3.34.1-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=sqlite-3.34.1-9.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "sqlite",
            "version": "3.34.1-9.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34743",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-34743",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in XZ Utils. When the `lzma_index_decoder()` function processes an empty index, and a subsequent `lzma_index_append()` operation is performed, insufficient memory is allocated. This can lead to a buffer overflow, potentially causing a denial of service (DoS) for affected systems.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34743",
            "epss": 0.0045,
            "percentile": 0.36788,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34743",
            "cwe": "CWE-122",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.23174999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34743",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34743",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87",
            "https://github.com/tukaani-project/xz/releases/tag/v5.8.3",
            "https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv",
            "http://www.openwall.com/lists/oss-security/2026/03/31/13",
            "https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"
          ],
          "description": "XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 1.7
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34743",
              "epss": 0.0045,
              "percentile": 0.36788,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34743",
              "cwe": "CWE-122",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "xz",
              "version": "5.2.5-8.el9_0"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34743",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "f3e667a0375f3959",
        "name": "xz-libs",
        "version": "5.2.5-8.el9_0",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:xz-libs:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*",
          "cpe:2.3:a:xz-libs:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*",
          "cpe:2.3:a:xz_libs:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*",
          "cpe:2.3:a:xz_libs:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*",
          "cpe:2.3:a:xz:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*",
          "cpe:2.3:a:xz:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=rhel-9.7&upstream=xz-5.2.5-8.el9_0.src.rpm",
        "upstreams": [
          {
            "name": "xz",
            "version": "5.2.5-8.el9_0"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-13176",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-13176",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A timing side-channel vulnerability was found in OpenSSL. This vulnerability allows an attacker to recover the private key. However, measuring the timing would require local access to the signing application or a fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This issue can happen with significant probability only for some of the supported elliptic curves. In particular, the NIST P-521 curve is affected.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-13176",
            "epss": 0.00601,
            "percentile": 0.45237,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-13176",
            "cwe": "CWE-385",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.231385
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-13176",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-13176",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844",
            "https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467",
            "https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902",
            "https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65",
            "https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f",
            "https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded",
            "https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86",
            "https://openssl-library.org/news/secadv/20250120.txt",
            "http://www.openwall.com/lists/oss-security/2025/01/20/2",
            "https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html",
            "https://security.netapp.com/advisory/ntap-20250124-0005/",
            "https://security.netapp.com/advisory/ntap-20250418-0010/",
            "https://security.netapp.com/advisory/ntap-20250502-0006/"
          ],
          "description": "Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 4.1,
                "exploitabilityScore": 0.7,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-13176",
              "epss": 0.00601,
              "percentile": 0.45237,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-13176",
              "cwe": "CWE-385",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-13176",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-13176",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-13176",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A timing side-channel vulnerability was found in OpenSSL. This vulnerability allows an attacker to recover the private key. However, measuring the timing would require local access to the signing application or a fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This issue can happen with significant probability only for some of the supported elliptic curves. In particular, the NIST P-521 curve is affected.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-13176",
            "epss": 0.00601,
            "percentile": 0.45237,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-13176",
            "cwe": "CWE-385",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.231385
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-13176",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-13176",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844",
            "https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467",
            "https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902",
            "https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65",
            "https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f",
            "https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded",
            "https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86",
            "https://openssl-library.org/news/secadv/20250120.txt",
            "http://www.openwall.com/lists/oss-security/2025/01/20/2",
            "https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html",
            "https://security.netapp.com/advisory/ntap-20250124-0005/",
            "https://security.netapp.com/advisory/ntap-20250418-0010/",
            "https://security.netapp.com/advisory/ntap-20250502-0006/"
          ],
          "description": "Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 4.1,
                "exploitabilityScore": 0.7,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-13176",
              "epss": 0.00601,
              "percentile": 0.45237,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-13176",
              "cwe": "CWE-385",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-13176",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42767",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42767",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. An attacker controlling a Certificate Management Protocol (CMP) server, or acting as a man-in-the-middle, could craft a malicious CMP response. This response, containing a Certificate Request Message Format (CRMF) CertRepMessage with a specific malformed EncryptedValue structure, would trigger a NULL pointer dereference in the OpenSSL CMP client. This vulnerability leads to a crash of the application, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.7,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42767",
            "epss": 0.00557,
            "percentile": 0.43127,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42767",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.23115500000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42767",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42767",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046",
            "https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774",
            "https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f",
            "https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873",
            "https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42767",
              "epss": 0.00557,
              "percentile": 0.43127,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42767",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42767",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42767",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42767",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. An attacker controlling a Certificate Management Protocol (CMP) server, or acting as a man-in-the-middle, could craft a malicious CMP response. This response, containing a Certificate Request Message Format (CRMF) CertRepMessage with a specific malformed EncryptedValue structure, would trigger a NULL pointer dereference in the OpenSSL CMP client. This vulnerability leads to a crash of the application, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.7,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42767",
            "epss": 0.00557,
            "percentile": 0.43127,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42767",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.23115500000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42767",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42767",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046",
            "https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774",
            "https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f",
            "https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873",
            "https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42767",
              "epss": 0.00557,
              "percentile": 0.43127,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42767",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42767",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-9150",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-9150",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-9150",
            "epss": 0.00399,
            "percentile": 0.3267,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-9150",
            "cwe": "CWE-121",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.22942499999999993
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-9150",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-9150",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:21333",
            "https://access.redhat.com/errata/RHSA-2026:28236",
            "https://access.redhat.com/errata/RHSA-2026:30649",
            "https://access.redhat.com/security/cve/CVE-2026-9150",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2460379",
            "https://github.com/openSUSE/libsolv/pull/616"
          ],
          "description": "A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-9150",
              "epss": 0.00399,
              "percentile": 0.3267,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-9150",
              "cwe": "CWE-121",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libsolv",
              "version": "0:0.7.24-3.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-9150",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "79ba35edcc44da5f",
        "name": "libsolv",
        "version": "0.7.24-3.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libsolv:libsolv:0.7.24-3.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libsolv:0.7.24-3.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libsolv@0.7.24-3.el9?arch=x86_64&distro=rhel-9.7&upstream=libsolv-0.7.24-3.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-14164",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-14164",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-14164",
            "epss": 0.00353,
            "percentile": 0.2795,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-14164",
            "cwe": "CWE-415",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.220625
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-14164",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-14164",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:30333",
            "https://access.redhat.com/security/cve/CVE-2026-14164",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2493411",
            "https://github.com/libarchive/libarchive/issues/3069",
            "https://github.com/libarchive/libarchive/pull/3071"
          ],
          "description": "A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-14164",
              "epss": 0.00353,
              "percentile": 0.2795,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-14164",
              "cwe": "CWE-415",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-14164",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34182",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-34182",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in OpenSSL's Cryptographic Message Services (CMS) AuthEnvelopedData processing. An on-path attacker can exploit insufficient input validation on cipher and tag length fields by sending specially crafted CMS messages. This can lead to the forging of messages or bypassing integrity validation. Consequently, an attacker may achieve key-equivalent functionality for a given CMS recipient.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 7.4,
              "exploitabilityScore": 2.3,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34182",
            "epss": 0.0035,
            "percentile": 0.27658,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34182",
            "cwe": "CWE-354",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.217
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34182",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34182",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://github.com/openssl/openssl/commit/03c1f4d45fb963aee7d5833390c507cd290182bc",
            "https://github.com/openssl/openssl/commit/439ed7d2c0962ce964482727264668bf277c333f",
            "https://github.com/openssl/openssl/commit/7947e6a81eb8776802f159fb6762cb7fcf7e34c7",
            "https://github.com/openssl/openssl/commit/9fd97f8cfdc2c0be214998de3b2b55c8edf6c7ac",
            "https://github.com/openssl/openssl/commit/d2ca86bcd43e4f17d899f347101766b6107676e0",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform\nsufficient input validation on the cipher and tag length fields of\nAuthEnvelopedData containers, leading to various potential compromises.\n\nImpact Summary: Attackers making use of these vulnerabilities may achieve\nkey-equivalent functionality for a given CMS recipient and/or bypass integrity\nvalidation for a given message.\n\nIn one use case, an attacker may send a CMS message containing\nAuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL\nerroneously allows this selection, and attempts to decrypt and validate the\nmessage.\n\nAn on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData\naddressed to the victim can re-emit it with the recipientInfos set left\nbyte-for-byte intact, so the victim's private key still unwraps the genuine CEK\n(the content-encryption key), but with the inner OID rewritten to AES-256-OFB\n(Output Feedback Mode, an unauthenticated keystream mode) and with an\nattacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the\nreal CEK, never consults the MAC field, and CMS_decrypt() returns success.\n\nIf the application under attack responds to the attacker with any indicator\nshowing success or failure of the decryption effort, it is possible for the\nattacker to use this as an oracle to obtain key equivalent functionality for the\nCEK used for the chosen recipient of the message.\n\nIn another use case, an attacker can reduce the tag length of the chosen AEAD\ncipher for a given AuthEnvelopedData container to be a single byte long,\nallowing an attacker to brute force CMS decryption, producing an integrity\nbypass for applications that trust CMS_decrypt() to reject modified content.\n\nThe FIPS modules are not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34182",
              "epss": 0.0035,
              "percentile": 0.27658,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34182",
              "cwe": "CWE-354",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34182",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34182",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-34182",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in OpenSSL's Cryptographic Message Services (CMS) AuthEnvelopedData processing. An on-path attacker can exploit insufficient input validation on cipher and tag length fields by sending specially crafted CMS messages. This can lead to the forging of messages or bypassing integrity validation. Consequently, an attacker may achieve key-equivalent functionality for a given CMS recipient.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 7.4,
              "exploitabilityScore": 2.3,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34182",
            "epss": 0.0035,
            "percentile": 0.27658,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34182",
            "cwe": "CWE-354",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.217
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34182",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34182",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://github.com/openssl/openssl/commit/03c1f4d45fb963aee7d5833390c507cd290182bc",
            "https://github.com/openssl/openssl/commit/439ed7d2c0962ce964482727264668bf277c333f",
            "https://github.com/openssl/openssl/commit/7947e6a81eb8776802f159fb6762cb7fcf7e34c7",
            "https://github.com/openssl/openssl/commit/9fd97f8cfdc2c0be214998de3b2b55c8edf6c7ac",
            "https://github.com/openssl/openssl/commit/d2ca86bcd43e4f17d899f347101766b6107676e0",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform\nsufficient input validation on the cipher and tag length fields of\nAuthEnvelopedData containers, leading to various potential compromises.\n\nImpact Summary: Attackers making use of these vulnerabilities may achieve\nkey-equivalent functionality for a given CMS recipient and/or bypass integrity\nvalidation for a given message.\n\nIn one use case, an attacker may send a CMS message containing\nAuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL\nerroneously allows this selection, and attempts to decrypt and validate the\nmessage.\n\nAn on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData\naddressed to the victim can re-emit it with the recipientInfos set left\nbyte-for-byte intact, so the victim's private key still unwraps the genuine CEK\n(the content-encryption key), but with the inner OID rewritten to AES-256-OFB\n(Output Feedback Mode, an unauthenticated keystream mode) and with an\nattacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the\nreal CEK, never consults the MAC field, and CMS_decrypt() returns success.\n\nIf the application under attack responds to the attacker with any indicator\nshowing success or failure of the decryption effort, it is possible for the\nattacker to use this as an oracle to obtain key equivalent functionality for the\nCEK used for the chosen recipient of the message.\n\nIn another use case, an attacker can reduce the tag length of the chosen AEAD\ncipher for a given AuthEnvelopedData container to be a single byte long,\nallowing an attacker to brute force CMS decryption, producing an integrity\nbypass for applications that trust CMS_decrypt() to reject modified content.\n\nThe FIPS modules are not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34182",
              "epss": 0.0035,
              "percentile": 0.27658,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34182",
              "cwe": "CWE-354",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34182",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42012",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42012",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N",
            "metrics": {
              "baseScore": 7.1,
              "exploitabilityScore": 2.9,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42012",
            "epss": 0.00354,
            "percentile": 0.28016,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42012",
            "cwe": "CWE-295",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.21416999999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42012",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42012",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-42012",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467441",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-7"
          ],
          "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 2.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42012",
              "epss": 0.00354,
              "percentile": 0.28016,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42012",
              "cwe": "CWE-295",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42012",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-58011",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-58011",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-58011",
            "epss": 0.0036,
            "percentile": 0.28572,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-58011",
            "cwe": "CWE-125",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.207
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-58011",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-58011",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-58011",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2492245",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3917",
            "https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"
          ],
          "description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-58011",
              "epss": 0.0036,
              "percentile": 0.28572,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-58011",
              "cwe": "CWE-125",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-58011",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6238",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-6238",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.3,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6238",
            "epss": 0.00358,
            "percentile": 0.28449,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6238",
            "cwe": "CWE-126",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-274.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-274.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42952",
            "link": "https://access.redhat.com/errata/RHSA-2026:42952"
          }
        ],
        "risk": 0.20584999999999995
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6238",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6238",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34069",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6238",
              "epss": 0.00358,
              "percentile": 0.28449,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6238",
              "cwe": "CWE-126",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "0:2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6238",
            "versionConstraint": "< 0:2.34-274.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-274.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "d41f8063e44e2263",
        "name": "glibc",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6238",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-6238",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.3,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6238",
            "epss": 0.00358,
            "percentile": 0.28449,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6238",
            "cwe": "CWE-126",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-274.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-274.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42952",
            "link": "https://access.redhat.com/errata/RHSA-2026:42952"
          }
        ],
        "risk": 0.20584999999999995
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6238",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6238",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34069",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6238",
              "epss": 0.00358,
              "percentile": 0.28449,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6238",
              "cwe": "CWE-126",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6238",
            "versionConstraint": "< 0:2.34-274.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-274.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "1135b72e9fa314da",
        "name": "glibc-common",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-common@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6238",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-6238",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.3,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6238",
            "epss": 0.00358,
            "percentile": 0.28449,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6238",
            "cwe": "CWE-126",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-274.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-274.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42952",
            "link": "https://access.redhat.com/errata/RHSA-2026:42952"
          }
        ],
        "risk": 0.20584999999999995
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6238",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6238",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34069",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6238",
              "epss": 0.00358,
              "percentile": 0.28449,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6238",
              "cwe": "CWE-126",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6238",
            "versionConstraint": "< 0:2.34-274.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-274.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "81f30677c0ddeeec",
        "name": "glibc-minimal-langpack",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42770",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42770",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. A malicious peer can exploit this vulnerability by presenting a specially crafted DHX (X9.42) peer key. Due to improper validation of the peer key's subgroup membership, an attacker can recover the victim's private key after a small number of key exchange attempts. This information disclosure can lead to unauthorized access or further compromise of affected systems.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42770",
            "epss": 0.00455,
            "percentile": 0.37149,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42770",
            "cwe": "CWE-325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.20247500000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42770",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42770",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02",
            "https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb",
            "https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c",
            "https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2",
            "https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42770",
              "epss": 0.00455,
              "percentile": 0.37149,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42770",
              "cwe": "CWE-325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42770",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42770",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42770",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. A malicious peer can exploit this vulnerability by presenting a specially crafted DHX (X9.42) peer key. Due to improper validation of the peer key's subgroup membership, an attacker can recover the victim's private key after a small number of key exchange attempts. This information disclosure can lead to unauthorized access or further compromise of affected systems.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42770",
            "epss": 0.00455,
            "percentile": 0.37149,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42770",
            "cwe": "CWE-325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.20247500000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42770",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42770",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02",
            "https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb",
            "https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c",
            "https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2",
            "https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42770",
              "epss": 0.00455,
              "percentile": 0.37149,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42770",
              "cwe": "CWE-325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42770",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-58013",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-58013",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-58013",
            "epss": 0.00349,
            "percentile": 0.27475,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-58013",
            "cwe": "CWE-126",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.200675
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-58013",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-58013",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-58013",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2492248",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3925"
          ],
          "description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 8.2,
                "exploitabilityScore": 3.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-58013",
              "epss": 0.00349,
              "percentile": 0.27475,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-58013",
              "cwe": "CWE-126",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-58013",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-58010",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-58010",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-58010",
            "epss": 0.00341,
            "percentile": 0.26717,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-58010",
            "cwe": "CWE-126",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.19607499999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-58010",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-58010",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-58010",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2492243",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3915"
          ],
          "description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 8.2,
                "exploitabilityScore": 3.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-58010",
              "epss": 0.00341,
              "percentile": 0.26717,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-58010",
              "cwe": "CWE-126",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-58010",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-58012",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-58012",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-58012",
            "epss": 0.00341,
            "percentile": 0.26717,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-58012",
            "cwe": "CWE-126",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.19607499999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-58012",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-58012",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-58012",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2492247",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3918"
          ],
          "description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 8.2,
                "exploitabilityScore": 3.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-58012",
              "epss": 0.00341,
              "percentile": 0.26717,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-58012",
              "cwe": "CWE-126",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-58012",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4046",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4046",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4046",
            "epss": 0.0038,
            "percentile": 0.30643,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4046",
            "cwe": "CWE-617",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-270.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-270.el9_8",
              "date": "2026-05-27",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20597",
            "link": "https://access.redhat.com/errata/RHSA-2026:20597"
          }
        ],
        "risk": 0.19569999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4046",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4046",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=33980",
            "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4046",
              "epss": 0.0038,
              "percentile": 0.30643,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4046",
              "cwe": "CWE-617",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "0:2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4046",
            "versionConstraint": "< 0:2.34-270.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-270.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "d41f8063e44e2263",
        "name": "glibc",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4046",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4046",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4046",
            "epss": 0.0038,
            "percentile": 0.30643,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4046",
            "cwe": "CWE-617",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-270.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-270.el9_8",
              "date": "2026-05-27",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20597",
            "link": "https://access.redhat.com/errata/RHSA-2026:20597"
          }
        ],
        "risk": 0.19569999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4046",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4046",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=33980",
            "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4046",
              "epss": 0.0038,
              "percentile": 0.30643,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4046",
              "cwe": "CWE-617",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4046",
            "versionConstraint": "< 0:2.34-270.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-270.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "1135b72e9fa314da",
        "name": "glibc-common",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-common@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4046",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4046",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4046",
            "epss": 0.0038,
            "percentile": 0.30643,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4046",
            "cwe": "CWE-617",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-270.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-270.el9_8",
              "date": "2026-05-27",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20597",
            "link": "https://access.redhat.com/errata/RHSA-2026:20597"
          }
        ],
        "risk": 0.19569999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4046",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4046",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=33980",
            "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4046",
              "epss": 0.0038,
              "percentile": 0.30643,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4046",
              "cwe": "CWE-617",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4046",
            "versionConstraint": "< 0:2.34-270.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-270.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "81f30677c0ddeeec",
        "name": "glibc-minimal-langpack",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-4156",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2023-4156",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.1,
              "exploitabilityScore": 1.9,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2023-4156",
            "epss": 0.00428,
            "percentile": 0.35098,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2023-4156",
            "cwe": "CWE-125",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2023-4156",
            "cwe": "CWE-125",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.19473999999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-4156",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-4156",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2023-4156",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2215930"
          ],
          "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 1.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 4.4,
                "exploitabilityScore": 1.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-4156",
              "epss": 0.00428,
              "percentile": 0.35098,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2023-4156",
              "cwe": "CWE-125",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2023-4156",
              "cwe": "CWE-125",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gawk",
              "version": "0:5.1.0-6.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-4156",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "9dcf052ea12fdad7",
        "name": "gawk",
        "version": "5.1.0-6.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and GPLv2+ and LGPLv2+ and BSD"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:gawk:5.1.0-6.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:gawk:gawk:5.1.0-6.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=rhel-9.7&upstream=gawk-5.1.0-6.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6653",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-6653",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libxml2. A remote attacker can exploit a use-after-free vulnerability in the `xmlParseInternalSubset` function by providing maliciously crafted XML input. This improper handling of entity resolution can lead to a denial-of-service (DoS), making the affected system or application unavailable.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6653",
            "epss": 0.00355,
            "percentile": 0.28183,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6653",
            "cwe": "CWE-416",
            "source": "security@ubuntu.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-6653",
            "cwe": "CWE-611",
            "source": "security@ubuntu.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.19347500000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6653",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6653",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260",
            "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"
          ],
          "description": "Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "security@ubuntu.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 7
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6653",
              "epss": 0.00355,
              "percentile": 0.28183,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6653",
              "cwe": "CWE-416",
              "source": "security@ubuntu.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-6653",
              "cwe": "CWE-611",
              "source": "security@ubuntu.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libxml2",
              "version": "0:2.9.13-14.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6653",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a840257087cebda4",
        "name": "libxml2",
        "version": "2.9.13-14.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libxml2-2.9.13-14.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4437",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4437",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc's DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4437",
            "epss": 0.00325,
            "percentile": 0.24931,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4437",
            "cwe": "CWE-125",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-270.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-270.el9_8",
              "date": "2026-05-27",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20597",
            "link": "https://access.redhat.com/errata/RHSA-2026:20597"
          }
        ],
        "risk": 0.18687499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4437",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4437",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34014",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4437",
              "epss": 0.00325,
              "percentile": 0.24931,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4437",
              "cwe": "CWE-125",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "0:2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4437",
            "versionConstraint": "< 0:2.34-270.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-270.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "d41f8063e44e2263",
        "name": "glibc",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4437",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4437",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc's DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4437",
            "epss": 0.00325,
            "percentile": 0.24931,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4437",
            "cwe": "CWE-125",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-270.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-270.el9_8",
              "date": "2026-05-27",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20597",
            "link": "https://access.redhat.com/errata/RHSA-2026:20597"
          }
        ],
        "risk": 0.18687499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4437",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4437",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34014",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4437",
              "epss": 0.00325,
              "percentile": 0.24931,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4437",
              "cwe": "CWE-125",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4437",
            "versionConstraint": "< 0:2.34-270.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-270.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "1135b72e9fa314da",
        "name": "glibc-common",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-common@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4437",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4437",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (the GNU C Library). When an application uses the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc's DNS backend, a remote attacker can send a specially crafted DNS (Domain Name System) response. This crafted response can cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer, leading to potential misbehavior or incorrect information processing.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4437",
            "epss": 0.00325,
            "percentile": 0.24931,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4437",
            "cwe": "CWE-125",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-270.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-270.el9_8",
              "date": "2026-05-27",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20597",
            "link": "https://access.redhat.com/errata/RHSA-2026:20597"
          }
        ],
        "risk": 0.18687499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4437",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4437",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34014",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4437",
              "epss": 0.00325,
              "percentile": 0.24931,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4437",
              "cwe": "CWE-125",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4437",
            "versionConstraint": "< 0:2.34-270.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-270.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "81f30677c0ddeeec",
        "name": "glibc-minimal-langpack",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-58014",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-58014",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "metrics": {
              "baseScore": 7.3,
              "exploitabilityScore": 3.9,
              "impactScore": 3.4
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-58014",
            "epss": 0.00302,
            "percentile": 0.22545,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-58014",
            "cwe": "CWE-193",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.18573
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-58014",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-58014",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-58014",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2492255",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3930"
          ],
          "description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
              "metrics": {
                "baseScore": 8.6,
                "exploitabilityScore": 3.9,
                "impactScore": 4.8
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 7.3,
                "exploitabilityScore": 3.9,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-58014",
              "epss": 0.00302,
              "percentile": 0.22545,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-58014",
              "cwe": "CWE-193",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-58014",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5928",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5928",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5928",
            "epss": 0.00369,
            "percentile": 0.29528,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5928",
            "cwe": "CWE-127",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-274.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-274.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42952",
            "link": "https://access.redhat.com/errata/RHSA-2026:42952"
          }
        ],
        "risk": 0.1845
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5928",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5928",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=33998",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5928",
              "epss": 0.00369,
              "percentile": 0.29528,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5928",
              "cwe": "CWE-127",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "0:2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5928",
            "versionConstraint": "< 0:2.34-274.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-274.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "d41f8063e44e2263",
        "name": "glibc",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5928",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5928",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5928",
            "epss": 0.00369,
            "percentile": 0.29528,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5928",
            "cwe": "CWE-127",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-274.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-274.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42952",
            "link": "https://access.redhat.com/errata/RHSA-2026:42952"
          }
        ],
        "risk": 0.1845
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5928",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5928",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=33998",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5928",
              "epss": 0.00369,
              "percentile": 0.29528,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5928",
              "cwe": "CWE-127",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5928",
            "versionConstraint": "< 0:2.34-274.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-274.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "1135b72e9fa314da",
        "name": "glibc-common",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-common@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5928",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5928",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5928",
            "epss": 0.00369,
            "percentile": 0.29528,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5928",
            "cwe": "CWE-127",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-274.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-274.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42952",
            "link": "https://access.redhat.com/errata/RHSA-2026:42952"
          }
        ],
        "risk": 0.1845
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5928",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5928",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=33998",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5928",
              "epss": 0.00369,
              "percentile": 0.29528,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5928",
              "cwe": "CWE-127",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5928",
            "versionConstraint": "< 0:2.34-274.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-274.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "81f30677c0ddeeec",
        "name": "glibc-minimal-langpack",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8926",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-8926",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When curl is configured to use a .netrc file for credentials and a URL is provided with a username but no password, curl may incorrectly retrieve and use the password for a different user from the .netrc file for the same host. This could lead to unauthorized information disclosure, as curl might connect using unintended credentials.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.8,
              "exploitabilityScore": 1.2,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8926",
            "epss": 0.00376,
            "percentile": 0.30278,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-8926",
            "cwe": "CWE-522",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.18424
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8926",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8926",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-8926.html",
            "https://curl.se/docs/CVE-2026-8926.json",
            "https://hackerone.com/reports/3735184"
          ],
          "description": "When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username(without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8926",
              "epss": 0.00376,
              "percentile": 0.30278,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-8926",
              "cwe": "CWE-522",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8926",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8926",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-8926",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When curl is configured to use a .netrc file for credentials and a URL is provided with a username but no password, curl may incorrectly retrieve and use the password for a different user from the .netrc file for the same host. This could lead to unauthorized information disclosure, as curl might connect using unintended credentials.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.8,
              "exploitabilityScore": 1.2,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8926",
            "epss": 0.00376,
            "percentile": 0.30278,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-8926",
            "cwe": "CWE-522",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.18424
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8926",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8926",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-8926.html",
            "https://curl.se/docs/CVE-2026-8926.json",
            "https://hackerone.com/reports/3735184"
          ],
          "description": "When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username(without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8926",
              "epss": 0.00376,
              "percentile": 0.30278,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-8926",
              "cwe": "CWE-522",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8926",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42769",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42769",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in the Certificate Management Protocol (CMP) implementation within OpenSSL. An attacker with existing Registration Authority (RA) level credentials could exploit an error in the certificate verification process during a Root Certificate Authority (CA) key update. This vulnerability allows the attacker to replace the root CA certificate for CMP clients with a fraudulent one. The primary consequence is an escalation of privileges, enabling the attacker to gain control equivalent to the root CA.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 0.8,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42769",
            "epss": 0.00401,
            "percentile": 0.32833,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42769",
            "cwe": "CWE-295",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.17844500000000002
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42769",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42769",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/54d0989997e5fc26057009a9782c3441ce3842fb",
            "https://github.com/openssl/openssl/commit/777b363b16fcf2153bb3ded39dc3838713667c44",
            "https://github.com/openssl/openssl/commit/d35cd473a271bf3ce7bf3d32af53217fb83ae92c",
            "https://github.com/openssl/openssl/commit/d531f21c0fe99067a66fc0ff1161ef127f9cd70b",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue Summary: An error in the callback used to verify the certificate\nprovided in a Root CA key update Certificate Management Protocol (CMP)\nmessage response rendered the certificate validation ineffectual, which\ncould lead to escalation of credentials from the Registration Authority (RA)\nlevel to the root Certification Authority (root CA) level.\n\nImpact Summary: The Registration Autority could replace the root CA\ncertificate for the CMP clients with an arbitrary root CA certificate.\n\nOne of the parts of the Certificate Management Protocol (CMP), specified in\nRFC 9810, is Root Certification Authority (root CA) key Rollover,\nwhich is sent by the server in a message with type 'id-it-rootCaKeyUpdate'.\nAs part of these messages, 'newWithOld' certificate, the new root CA\ncertificate signed with the old root CA key, is provided, and verifying its\nsignature is crucial for transferring the trust from the old CA key to the\nnew one.\n\nThe 'id-it-rootCaKeyUpdate' messages are expected to be processed with\nOSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld'\ncertificate.  A typo in the certificate chain building code led to adding\nan incorrect certificate ('newWithOld' instead of 'oldRoot') to the\ncertificate chain, rendering the certificate verification process ineffectual\n(only the issuer name and the algorithm OIDs were verified by other parts\nof the verification code).\n\nAn attacker who already has credentials that satisfy the CMP message\nprotection checks can generate a new key pair and use a crafted self-signed\ncertificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP\nclients would accept as a new trust anchor.\n\nSignificant preconditions for the attack (having valid RA-level credentials)\nare the reason the issue was assigned Low severity.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42769",
              "epss": 0.00401,
              "percentile": 0.32833,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42769",
              "cwe": "CWE-295",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42769",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42769",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42769",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in the Certificate Management Protocol (CMP) implementation within OpenSSL. An attacker with existing Registration Authority (RA) level credentials could exploit an error in the certificate verification process during a Root Certificate Authority (CA) key update. This vulnerability allows the attacker to replace the root CA certificate for CMP clients with a fraudulent one. The primary consequence is an escalation of privileges, enabling the attacker to gain control equivalent to the root CA.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 0.8,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42769",
            "epss": 0.00401,
            "percentile": 0.32833,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42769",
            "cwe": "CWE-295",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.17844500000000002
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42769",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42769",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/54d0989997e5fc26057009a9782c3441ce3842fb",
            "https://github.com/openssl/openssl/commit/777b363b16fcf2153bb3ded39dc3838713667c44",
            "https://github.com/openssl/openssl/commit/d35cd473a271bf3ce7bf3d32af53217fb83ae92c",
            "https://github.com/openssl/openssl/commit/d531f21c0fe99067a66fc0ff1161ef127f9cd70b",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue Summary: An error in the callback used to verify the certificate\nprovided in a Root CA key update Certificate Management Protocol (CMP)\nmessage response rendered the certificate validation ineffectual, which\ncould lead to escalation of credentials from the Registration Authority (RA)\nlevel to the root Certification Authority (root CA) level.\n\nImpact Summary: The Registration Autority could replace the root CA\ncertificate for the CMP clients with an arbitrary root CA certificate.\n\nOne of the parts of the Certificate Management Protocol (CMP), specified in\nRFC 9810, is Root Certification Authority (root CA) key Rollover,\nwhich is sent by the server in a message with type 'id-it-rootCaKeyUpdate'.\nAs part of these messages, 'newWithOld' certificate, the new root CA\ncertificate signed with the old root CA key, is provided, and verifying its\nsignature is crucial for transferring the trust from the old CA key to the\nnew one.\n\nThe 'id-it-rootCaKeyUpdate' messages are expected to be processed with\nOSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld'\ncertificate.  A typo in the certificate chain building code led to adding\nan incorrect certificate ('newWithOld' instead of 'oldRoot') to the\ncertificate chain, rendering the certificate verification process ineffectual\n(only the issuer name and the algorithm OIDs were verified by other parts\nof the verification code).\n\nAn attacker who already has credentials that satisfy the CMP message\nprotection checks can generate a new key pair and use a crafted self-signed\ncertificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP\nclients would accept as a new trust anchor.\n\nSignificant preconditions for the attack (having valid RA-level credentials)\nare the reason the issue was assigned Low severity.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42769",
              "epss": 0.00401,
              "percentile": 0.32833,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42769",
              "cwe": "CWE-295",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42769",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-3783",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-3783",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When an OAuth2 bearer token is used for an HTTP(S) transfer that redirects to a second URL, curl could unintentionally leak the token. This occurs if the second hostname has entries in the `.netrc` file, allowing the bearer token intended for the first host to be sent to the redirected host. This information disclosure could allow an attacker to gain unauthorized access.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.7,
              "exploitabilityScore": 2.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-3783",
            "epss": 0.00333,
            "percentile": 0.25811,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-3783",
            "cwe": "CWE-522",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.17815500000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-3783",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-3783",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-3783.html",
            "https://curl.se/docs/CVE-2026-3783.json",
            "https://hackerone.com/reports/3583983",
            "http://www.openwall.com/lists/oss-security/2026/03/11/2"
          ],
          "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-3783",
              "epss": 0.00333,
              "percentile": 0.25811,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-3783",
              "cwe": "CWE-522",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-3783",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-3783",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-3783",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When an OAuth2 bearer token is used for an HTTP(S) transfer that redirects to a second URL, curl could unintentionally leak the token. This occurs if the second hostname has entries in the `.netrc` file, allowing the bearer token intended for the first host to be sent to the redirected host. This information disclosure could allow an attacker to gain unauthorized access.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.7,
              "exploitabilityScore": 2.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-3783",
            "epss": 0.00333,
            "percentile": 0.25811,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-3783",
            "cwe": "CWE-522",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.17815500000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-3783",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-3783",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-3783.html",
            "https://curl.se/docs/CVE-2026-3783.json",
            "https://hackerone.com/reports/3583983",
            "http://www.openwall.com/lists/oss-security/2026/03/11/2"
          ],
          "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-3783",
              "epss": 0.00333,
              "percentile": 0.25811,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-3783",
              "cwe": "CWE-522",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-3783",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4426",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4426",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4426",
            "epss": 0.00305,
            "percentile": 0.22832,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4426",
            "cwe": "CWE-1335",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.17537499999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4426",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4426",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:8944",
            "https://access.redhat.com/security/cve/CVE-2026-4426",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2449010",
            "https://github.com/libarchive/libarchive/pull/2897"
          ],
          "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4426",
              "epss": 0.00305,
              "percentile": 0.22832,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4426",
              "cwe": "CWE-1335",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4426",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-3784",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-3784",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy connection when performing a CONNECT request to a server, even if the new request uses different authentication credentials for the HTTP proxy. This improper connection reuse could lead to an attacker gaining unauthorized access to resources or information intended for a different user.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-3784",
            "epss": 0.00302,
            "percentile": 0.22457,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-3784",
            "cwe": "CWE-305",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.17365
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-3784",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-3784.html",
            "https://curl.se/docs/CVE-2026-3784.json",
            "https://hackerone.com/reports/3584903",
            "http://www.openwall.com/lists/oss-security/2026/03/11/3",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
          ],
          "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-3784",
              "epss": 0.00302,
              "percentile": 0.22457,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-3784",
              "cwe": "CWE-305",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-3784",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-3784",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-3784",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy connection when performing a CONNECT request to a server, even if the new request uses different authentication credentials for the HTTP proxy. This improper connection reuse could lead to an attacker gaining unauthorized access to resources or information intended for a different user.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-3784",
            "epss": 0.00302,
            "percentile": 0.22457,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-3784",
            "cwe": "CWE-305",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.17365
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-3784",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-3784.html",
            "https://curl.se/docs/CVE-2026-3784.json",
            "https://hackerone.com/reports/3584903",
            "http://www.openwall.com/lists/oss-security/2026/03/11/3",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
          ],
          "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-3784",
              "epss": 0.00302,
              "percentile": 0.22457,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-3784",
              "cwe": "CWE-305",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-3784",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4873",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4873",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. A remote attacker could exploit this by initiating an unencrypted connection (via IMAP, SMTP, or POP3) and then making a subsequent request to the same host that requires Transport Layer Security (TLS). Due to incorrect connection reuse, the subsequent request would bypass the TLS requirement, leading to the transmission of sensitive information in cleartext. This vulnerability, categorized as Cleartext Transmission of Sensitive Information (CWE-319), results in information disclosure.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.7,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4873",
            "epss": 0.00329,
            "percentile": 0.2535,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4873",
            "cwe": "CWE-295",
            "source": "nvd@nist.gov",
            "type": "Primary"
          },
          {
            "cve": "CVE-2026-4873",
            "cwe": "CWE-319",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.169435
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4873",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-4873.html",
            "https://curl.se/docs/CVE-2026-4873.json",
            "https://hackerone.com/reports/3621851",
            "http://www.openwall.com/lists/oss-security/2026/04/29/7"
          ],
          "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4873",
              "epss": 0.00329,
              "percentile": 0.2535,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4873",
              "cwe": "CWE-295",
              "source": "nvd@nist.gov",
              "type": "Primary"
            },
            {
              "cve": "CVE-2026-4873",
              "cwe": "CWE-319",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4873",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4873",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4873",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. A remote attacker could exploit this by initiating an unencrypted connection (via IMAP, SMTP, or POP3) and then making a subsequent request to the same host that requires Transport Layer Security (TLS). Due to incorrect connection reuse, the subsequent request would bypass the TLS requirement, leading to the transmission of sensitive information in cleartext. This vulnerability, categorized as Cleartext Transmission of Sensitive Information (CWE-319), results in information disclosure.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.7,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4873",
            "epss": 0.00329,
            "percentile": 0.2535,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4873",
            "cwe": "CWE-295",
            "source": "nvd@nist.gov",
            "type": "Primary"
          },
          {
            "cve": "CVE-2026-4873",
            "cwe": "CWE-319",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.169435
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4873",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-4873.html",
            "https://curl.se/docs/CVE-2026-4873.json",
            "https://hackerone.com/reports/3621851",
            "http://www.openwall.com/lists/oss-security/2026/04/29/7"
          ],
          "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4873",
              "epss": 0.00329,
              "percentile": 0.2535,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4873",
              "cwe": "CWE-295",
              "source": "nvd@nist.gov",
              "type": "Primary"
            },
            {
              "cve": "CVE-2026-4873",
              "cwe": "CWE-319",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4873",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-1489",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-1489",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 5.4,
              "exploitabilityScore": 2.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-1489",
            "epss": 0.00325,
            "percentile": 0.25012,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-1489",
            "cwe": "CWE-787",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.16899999999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-1489",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-1489",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-1489",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2433348",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3872",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
          ],
          "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
              "metrics": {
                "baseScore": 5.4,
                "exploitabilityScore": 2.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-1489",
              "epss": 0.00325,
              "percentile": 0.25012,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-1489",
              "cwe": "CWE-787",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-1489",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-9149",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-9149",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-9149",
            "epss": 0.00291,
            "percentile": 0.21321,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-9149",
            "cwe": "CWE-122",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.16732499999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-9149",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-9149",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:21333",
            "https://access.redhat.com/errata/RHSA-2026:28236",
            "https://access.redhat.com/security/cve/CVE-2026-9149",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2460380",
            "https://github.com/openSUSE/libsolv/pull/617"
          ],
          "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-9149",
              "epss": 0.00291,
              "percentile": 0.21321,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-9149",
              "cwe": "CWE-122",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libsolv",
              "version": "0:0.7.24-3.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-9149",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "79ba35edcc44da5f",
        "name": "libsolv",
        "version": "0.7.24-3.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libsolv:libsolv:0.7.24-3.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libsolv:0.7.24-3.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libsolv@0.7.24-3.el9?arch=x86_64&distro=rhel-9.7&upstream=libsolv-0.7.24-3.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-54411",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-54411",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in Linux-PAM's `pam_userdb` module. This vulnerability, categorized as an Observable Timing Discrepancy (CWE-208), allows a local or network-adjacent attacker to recover plaintext passwords. By repeatedly attempting authentication and measuring response-timing differences during plaintext password comparison, an attacker can deduce the password. This flaw is exploitable when the `pam_userdb` module is configured to store and compare credentials in plaintext, which is not a default setting.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.8,
              "exploitabilityScore": 1.2,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-54411",
            "epss": 0.00333,
            "percentile": 0.25801,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-54411",
            "cwe": "CWE-208",
            "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.16317
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-54411",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-54411",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://cwe.mitre.org/data/definitions/208.html",
            "https://github.com/linux-pam/linux-pam",
            "https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h",
            "https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"
          ],
          "description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.",
          "cvss": [
            {
              "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X",
              "metrics": {
                "baseScore": 6.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-54411",
              "epss": 0.00333,
              "percentile": 0.25801,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-54411",
              "cwe": "CWE-208",
              "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "pam",
              "version": "0:1.5.1-26.el9_6"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-54411",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "9dd847ac0d635e43",
        "name": "pam",
        "version": "1.5.1-26.el9_6",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD and GPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:pam:1.5.1-26.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:pam:pam:1.5.1-26.el9_6:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/pam@1.5.1-26.el9_6?arch=x86_64&distro=rhel-9.7&upstream=pam-1.5.1-26.el9_6.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-51296",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-51296",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in SQLite. A use-after-free vulnerability in the SQLite JSON module's jsonRemoveFunc allows a remote attacker to cause a denial of service by crashing the service. This vulnerability can also lead to the disclosure of sensitive heap memory information.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 8.2,
              "exploitabilityScore": 3.9,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-51296",
            "epss": 0.00204,
            "percentile": 0.10594,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-51296",
            "cwe": "CWE-416",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.16014
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-51296",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-51296",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/programmervuln/cveadvisory-/commit/75a435c839a4bcc6ca2ad21e3b07c978d814acb2",
            "https://github.com/sqlite/sqlite/blob/master/src/json.c"
          ],
          "description": "SQLite 3.41 has a use-after-free vulnerability in jsonRemoveFunc of SQLite JSON module. The parsed JSON object is freed at line 3555, while line 3575 still calls jsonLookupStep with the released pointer. Remote attackers can exploit this flaw to crash the service and leak heap memory information.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-51296",
              "epss": 0.00204,
              "percentile": 0.10594,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-51296",
              "cwe": "CWE-416",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "sqlite",
              "version": "3.34.1-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-51296",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "1bd197aae1b6fd3b",
        "name": "sqlite-libs",
        "version": "3.34.1-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/sqlite-libs@3.34.1-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=sqlite-3.34.1-9.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "sqlite",
            "version": "3.34.1-9.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-15224",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-15224",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libcurl. When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-15224",
            "epss": 0.00413,
            "percentile": 0.33881,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-15224",
            "cwe": "CWE-287",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.159005
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-15224",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://curl.se/docs/CVE-2025-15224.html",
            "https://curl.se/docs/CVE-2025-15224.json",
            "https://hackerone.com/reports/3480925",
            "http://www.openwall.com/lists/oss-security/2026/01/07/7"
          ],
          "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 3.1,
                "exploitabilityScore": 1.7,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-15224",
              "epss": 0.00413,
              "percentile": 0.33881,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-15224",
              "cwe": "CWE-287",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-15224",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-15224",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-15224",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libcurl. When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-15224",
            "epss": 0.00413,
            "percentile": 0.33881,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-15224",
            "cwe": "CWE-287",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.159005
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-15224",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://curl.se/docs/CVE-2025-15224.html",
            "https://curl.se/docs/CVE-2025-15224.json",
            "https://hackerone.com/reports/3480925",
            "http://www.openwall.com/lists/oss-security/2026/01/07/7"
          ],
          "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 3.1,
                "exploitabilityScore": 1.7,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-15224",
              "epss": 0.00413,
              "percentile": 0.33881,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-15224",
              "cwe": "CWE-287",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-15224",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-1965",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-1965",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When an application uses libcurl to make multiple Negotiate-authenticated HTTP or HTTPS requests to the same server with different credentials, libcurl may incorrectly reuse an existing connection. This logical error can cause a subsequent request to be sent using the authentication of a previous user, leading to an authentication bypass.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 1.7,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-1965",
            "epss": 0.00259,
            "percentile": 0.17569,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-1965",
            "cwe": "CWE-305",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.15281
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-1965",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-1965",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-1965.html",
            "https://curl.se/docs/CVE-2026-1965.json"
          ],
          "description": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-1965",
              "epss": 0.00259,
              "percentile": 0.17569,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-1965",
              "cwe": "CWE-305",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-1965",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-1965",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-1965",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When an application uses libcurl to make multiple Negotiate-authenticated HTTP or HTTPS requests to the same server with different credentials, libcurl may incorrectly reuse an existing connection. This logical error can cause a subsequent request to be sent using the authentication of a previous user, leading to an authentication bypass.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 1.7,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-1965",
            "epss": 0.00259,
            "percentile": 0.17569,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-1965",
            "cwe": "CWE-305",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.15281
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-1965",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-1965",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-1965.html",
            "https://curl.se/docs/CVE-2026-1965.json"
          ],
          "description": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-1965",
              "epss": 0.00259,
              "percentile": 0.17569,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-1965",
              "cwe": "CWE-305",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-1965",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-24883",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-24883",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in GnuPG. A remote attacker could provide a specially crafted long signature packet that, when processed, causes the application to crash. This vulnerability leads to a denial of service (DoS), making the GnuPG application unavailable to legitimate users.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-24883",
            "epss": 0.00447,
            "percentile": 0.36635,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-24883",
            "cwe": "CWE-476",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.149745
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-24883",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-24883",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://dev.gnupg.org/T8049",
            "https://www.openwall.com/lists/oss-security/2026/01/27/8"
          ],
          "description": "In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-24883",
              "epss": 0.00447,
              "percentile": 0.36635,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-24883",
              "cwe": "CWE-476",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnupg2",
              "version": "0:2.3.3-5.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-24883",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "6612ed205a98e91d",
        "name": "gnupg2",
        "version": "2.3.3-5.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+"
        ],
        "cpes": [
          "cpe:2.3:a:gnupg2:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnupg2-2.3.3-5.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-3360",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-3360",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-3360",
            "epss": 0.00447,
            "percentile": 0.36619,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-3360",
            "cwe": "CWE-190",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.149745
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-3360",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-3360",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2025-3360",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2357754",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3647",
            "https://lists.debian.org/debian-lts-announce/2025/04/msg00024.html",
            "https://gitlab.gnome.org/GNOME/glib/-/work_items/3647"
          ],
          "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-3360",
              "epss": 0.00447,
              "percentile": 0.36619,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-3360",
              "cwe": "CWE-190",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-3360",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-0989",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-0989",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-0989",
            "epss": 0.00438,
            "percentile": 0.3593,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-0989",
            "cwe": "CWE-674",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.14673
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-0989",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-0989",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:7519",
            "https://access.redhat.com/security/cve/CVE-2026-0989",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2429933",
            "https://gitlab.gnome.org/GNOME/libxml2/-/issues/998"
          ],
          "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-0989",
              "epss": 0.00438,
              "percentile": 0.3593,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-0989",
              "cwe": "CWE-674",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libxml2",
              "version": "0:2.9.13-14.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-0989",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a840257087cebda4",
        "name": "libxml2",
        "version": "2.9.13-14.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libxml2-2.9.13-14.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4878",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4878",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 6.7,
              "exploitabilityScore": 0.8,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4878",
            "epss": 0.00206,
            "percentile": 0.10855,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4878",
            "cwe": "CWE-367",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-4878",
            "cwe": "CWE-367",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.48-10.el9_7.1"
          ],
          "state": "fixed"
        },
        "advisories": [
          {
            "id": "RHSA-2026:12441",
            "link": "https://access.redhat.com/errata/RHSA-2026:12441"
          }
        ],
        "risk": 0.14626
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4878",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4878",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:12423",
            "https://access.redhat.com/errata/RHSA-2026:12441",
            "https://access.redhat.com/errata/RHSA-2026:13285",
            "https://access.redhat.com/errata/RHSA-2026:14162",
            "https://access.redhat.com/errata/RHSA-2026:14937",
            "https://access.redhat.com/errata/RHSA-2026:19130",
            "https://access.redhat.com/errata/RHSA-2026:19346",
            "https://access.redhat.com/errata/RHSA-2026:19456",
            "https://access.redhat.com/errata/RHSA-2026:19458",
            "https://access.redhat.com/errata/RHSA-2026:20595",
            "https://access.redhat.com/errata/RHSA-2026:21254",
            "https://access.redhat.com/errata/RHSA-2026:21275",
            "https://access.redhat.com/errata/RHSA-2026:22634",
            "https://access.redhat.com/errata/RHSA-2026:22957",
            "https://access.redhat.com/errata/RHSA-2026:23233",
            "https://access.redhat.com/errata/RHSA-2026:23245",
            "https://access.redhat.com/errata/RHSA-2026:24346",
            "https://access.redhat.com/errata/RHSA-2026:25044",
            "https://access.redhat.com/errata/RHSA-2026:25096",
            "https://access.redhat.com/errata/RHSA-2026:25181",
            "https://access.redhat.com/errata/RHSA-2026:26542",
            "https://access.redhat.com/errata/RHSA-2026:27998",
            "https://access.redhat.com/errata/RHSA-2026:28887",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30078",
            "https://access.redhat.com/errata/RHSA-2026:30087",
            "https://access.redhat.com/errata/RHSA-2026:30088",
            "https://access.redhat.com/errata/RHSA-2026:30089",
            "https://access.redhat.com/errata/RHSA-2026:34098",
            "https://access.redhat.com/errata/RHSA-2026:39981",
            "https://access.redhat.com/errata/RHSA-2026:7473",
            "https://access.redhat.com/security/cve/CVE-2026-4878",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2447554",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2451615",
            "http://www.openwall.com/lists/oss-security/2026/04/07/14",
            "http://www.openwall.com/lists/oss-security/2026/04/07/4",
            "http://www.openwall.com/lists/oss-security/2026/04/08/9",
            "http://www.openwall.com/lists/oss-security/2026/04/09/5",
            "http://www.openwall.com/lists/oss-security/2026/04/09/6",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4878.json"
          ],
          "description": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 7,
                "exploitabilityScore": 1.1,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 6.7,
                "exploitabilityScore": 0.8,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 6.7,
                "exploitabilityScore": 0.8,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4878",
              "epss": 0.00206,
              "percentile": 0.10855,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4878",
              "cwe": "CWE-367",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-4878",
              "cwe": "CWE-367",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libcap",
              "version": "0:2.48-10.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4878",
            "versionConstraint": "< 0:2.48-10.el9_7.1 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.48-10.el9_7.1"
          }
        }
      ],
      "artifact": {
        "id": "0e9353c95034199a",
        "name": "libcap",
        "version": "2.48-10.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD or GPLv2"
        ],
        "cpes": [
          "cpe:2.3:a:libcap:libcap:2.48-10.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcap:2.48-10.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcap@2.48-10.el9?arch=x86_64&distro=rhel-9.7&upstream=libcap-2.48-10.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-50219",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-50219",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libexpat. This vulnerability occurs because the library, in versions before 2.8.2, does not properly track handler call depth when certain XML parsing functions are invoked from within handlers during a policy violation. This oversight can lead to a use-after-free condition, which may result in information disclosure, integrity loss, or denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "metrics": {
              "baseScore": 4.9,
              "exploitabilityScore": 1.5,
              "impactScore": 3.4
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-50219",
            "epss": 0.00288,
            "percentile": 0.21022,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-50219",
            "cwe": "CWE-416",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.14256000000000002
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-50219",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-50219",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/libexpat/libexpat/pull/1246"
          ],
          "description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.6,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 4.9,
                "exploitabilityScore": 1.5,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-50219",
              "epss": 0.00288,
              "percentile": 0.21022,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-50219",
              "cwe": "CWE-416",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-50219",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-1484",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-1484",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 4.2,
              "exploitabilityScore": 1.7,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-1484",
            "epss": 0.00304,
            "percentile": 0.22697,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-1484",
            "cwe": "CWE-787",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.13984000000000002
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-1484",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-1484",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-1484",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2433259",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3870",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
          ],
          "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L",
              "metrics": {
                "baseScore": 4.2,
                "exploitabilityScore": 1.7,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-1484",
              "epss": 0.00304,
              "percentile": 0.22697,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-1484",
              "cwe": "CWE-787",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-1484",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2022-3219",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2022-3219",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A vulnerability was found in GnuPG. GnuPG can spin on a relatively small input by crafting a public key with thousands of signatures attached and compressed down to a few kilobytes. This issue can potentially cause a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.2,
              "exploitabilityScore": 2.6,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2022-3219",
            "epss": 0.00293,
            "percentile": 0.21521,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2022-3219",
            "cwe": "CWE-787",
            "source": "nvd@nist.gov",
            "type": "Primary"
          },
          {
            "cve": "CVE-2022-3219",
            "cwe": "CWE-787",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.13477999999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2022-3219",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2022-3219",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2022-3219",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2127010",
            "https://dev.gnupg.org/D556",
            "https://dev.gnupg.org/T5993",
            "https://marc.info/?l=oss-security&m=165696590211434&w=4",
            "https://security.netapp.com/advisory/ntap-20230324-0001/"
          ],
          "description": "GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 3.3,
                "exploitabilityScore": 1.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 3.3,
                "exploitabilityScore": 1.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2022-3219",
              "epss": 0.00293,
              "percentile": 0.21521,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2022-3219",
              "cwe": "CWE-787",
              "source": "nvd@nist.gov",
              "type": "Primary"
            },
            {
              "cve": "CVE-2022-3219",
              "cwe": "CWE-787",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnupg2",
              "version": "0:2.3.3-5.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2022-3219",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "6612ed205a98e91d",
        "name": "gnupg2",
        "version": "2.3.3-5.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+"
        ],
        "cpes": [
          "cpe:2.3:a:gnupg2:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnupg2-2.3.3-5.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-13034",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-13034",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When configured to use public key pinning with QUIC connections and GnuTLS, and with standard certificate verification explicitly disabled, curl could bypass the intended public key check. This oversight allows a malicious server to impersonate a legitimate one, potentially leading to unauthorized access or information disclosure due to a failure in verifying the server's identity.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 1.7,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-13034",
            "epss": 0.00227,
            "percentile": 0.13565,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-13034",
            "cwe": "CWE-295",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.13393
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-13034",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-13034",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-13034.html",
            "https://curl.se/docs/CVE-2025-13034.json"
          ],
          "description": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool,curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-13034",
              "epss": 0.00227,
              "percentile": 0.13565,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-13034",
              "cwe": "CWE-295",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-13034",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-13034",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-13034",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When configured to use public key pinning with QUIC connections and GnuTLS, and with standard certificate verification explicitly disabled, curl could bypass the intended public key check. This oversight allows a malicious server to impersonate a legitimate one, potentially leading to unauthorized access or information disclosure due to a failure in verifying the server's identity.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 1.7,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-13034",
            "epss": 0.00227,
            "percentile": 0.13565,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-13034",
            "cwe": "CWE-295",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.13393
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-13034",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-13034",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-13034.html",
            "https://curl.se/docs/CVE-2025-13034.json"
          ],
          "description": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool,curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-13034",
              "epss": 0.00227,
              "percentile": 0.13565,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-13034",
              "cwe": "CWE-295",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-13034",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-41080",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-41080",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing a specially crafted XML document that leverages insufficient entropy in the hash function. This can lead to hash flooding, a type of Denial of Service (DoS) attack, where the system becomes unresponsive or crashes due to excessive resource consumption.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-41080",
            "epss": 0.00398,
            "percentile": 0.32501,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-41080",
            "cwe": "CWE-331",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.13333
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-41080",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-41080",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://blog.hartwork.org/posts/expat-2-8-0-released/",
            "https://github.com/libexpat/libexpat/issues/47",
            "https://github.com/libexpat/libexpat/pull/1183",
            "https://www.openwall.com/lists/oss-security/2026/04/26/1",
            "http://www.openwall.com/lists/oss-security/2026/04/26/1",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-41080",
              "epss": 0.00398,
              "percentile": 0.32501,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-41080",
              "cwe": "CWE-331",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-41080",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-0988",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-0988",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-0988",
            "epss": 0.00396,
            "percentile": 0.32329,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-0988",
            "cwe": "CWE-190",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.13265999999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-0988",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-0988",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:7461",
            "https://access.redhat.com/security/cve/CVE-2026-0988",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2429886",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3851"
          ],
          "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-0988",
              "epss": 0.00396,
              "percentile": 0.32329,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-0988",
              "cwe": "CWE-190",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-0988",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-0232",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2024-0232",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2024-0232",
            "epss": 0.00343,
            "percentile": 0.2691,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-0232",
            "cwe": "CWE-416",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2024-0232",
            "cwe": "CWE-416",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.132055
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-0232",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-0232",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2024-0232",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2243754",
            "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/",
            "https://security.netapp.com/advisory/ntap-20240315-0007/"
          ],
          "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-0232",
              "epss": 0.00343,
              "percentile": 0.2691,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-0232",
              "cwe": "CWE-416",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2024-0232",
              "cwe": "CWE-416",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "sqlite",
              "version": "3.34.1-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-0232",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "1bd197aae1b6fd3b",
        "name": "sqlite-libs",
        "version": "3.34.1-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/sqlite-libs@3.34.1-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=sqlite-3.34.1-9.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "sqlite",
            "version": "3.34.1-9.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-48864",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-48864",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 7.8,
              "exploitabilityScore": 1.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-48864",
            "epss": 0.00205,
            "percentile": 0.10723,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-48864",
            "cwe": "CWE-787",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:0.7.24-6.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:0.7.24-6.el9_8",
              "date": "2026-07-15",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:39315",
            "link": "https://access.redhat.com/errata/RHSA-2026:39315"
          }
        ],
        "risk": 0.1312
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-48864",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-48864",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:21333",
            "https://access.redhat.com/errata/RHSA-2026:28236",
            "https://access.redhat.com/errata/RHSA-2026:36730",
            "https://access.redhat.com/errata/RHSA-2026:39315",
            "https://access.redhat.com/errata/RHSA-2026:44481",
            "https://access.redhat.com/errata/RHSA-2026:46836",
            "https://access.redhat.com/security/cve/CVE-2026-48864",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
          ],
          "description": "A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 7.8,
                "exploitabilityScore": 1.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-48864",
              "epss": 0.00205,
              "percentile": 0.10723,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-48864",
              "cwe": "CWE-787",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libsolv",
              "version": "0:0.7.24-3.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-48864",
            "versionConstraint": "< 0:0.7.24-6.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:0.7.24-6.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "79ba35edcc44da5f",
        "name": "libsolv",
        "version": "0.7.24-3.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libsolv:libsolv:0.7.24-3.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libsolv:0.7.24-3.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libsolv@0.7.24-3.el9?arch=x86_64&distro=rhel-9.7&upstream=libsolv-0.7.24-3.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11850",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-11850",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-11850",
            "epss": 0.00261,
            "percentile": 0.17805,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11850",
            "cwe": "CWE-191",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.1305
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11850",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:25520",
            "https://access.redhat.com/security/cve/CVE-2026-11850",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
          ],
          "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 0.8,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11850",
              "epss": 0.00261,
              "percentile": 0.17805,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11850",
              "cwe": "CWE-191",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "krb5",
              "version": "1.21.1-8.el9_6"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11850",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a9ecfba863face9a",
        "name": "krb5-libs",
        "version": "1.21.1-8.el9_6",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:krb5-libs:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5-libs:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5_libs:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5_libs:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5:krb5-libs:1.21.1-8.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:krb5:krb5_libs:1.21.1-8.el9_6:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/krb5-libs@1.21.1-8.el9_6?arch=x86_64&distro=rhel-9.7&upstream=krb5-1.21.1-8.el9_6.src.rpm",
        "upstreams": [
          {
            "name": "krb5",
            "version": "1.21.1-8.el9_6"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5435",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5435",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 1.7,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5435",
            "epss": 0.00237,
            "percentile": 0.1487,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5435",
            "cwe": "CWE-787",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-274.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-274.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42952",
            "link": "https://access.redhat.com/errata/RHSA-2026:42952"
          }
        ],
        "risk": 0.129165
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5435",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5435",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34033",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 7.3,
                "exploitabilityScore": 3.9,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5435",
              "epss": 0.00237,
              "percentile": 0.1487,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5435",
              "cwe": "CWE-787",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "0:2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5435",
            "versionConstraint": "< 0:2.34-274.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-274.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "d41f8063e44e2263",
        "name": "glibc",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5435",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5435",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 1.7,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5435",
            "epss": 0.00237,
            "percentile": 0.1487,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5435",
            "cwe": "CWE-787",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-274.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-274.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42952",
            "link": "https://access.redhat.com/errata/RHSA-2026:42952"
          }
        ],
        "risk": 0.129165
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5435",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5435",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34033",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 7.3,
                "exploitabilityScore": 3.9,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5435",
              "epss": 0.00237,
              "percentile": 0.1487,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5435",
              "cwe": "CWE-787",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5435",
            "versionConstraint": "< 0:2.34-274.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-274.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "1135b72e9fa314da",
        "name": "glibc-common",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-common@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5435",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5435",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 1.7,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5435",
            "epss": 0.00237,
            "percentile": 0.1487,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5435",
            "cwe": "CWE-787",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-274.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-274.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42952",
            "link": "https://access.redhat.com/errata/RHSA-2026:42952"
          }
        ],
        "risk": 0.129165
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5435",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5435",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34033",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 7.3,
                "exploitabilityScore": 3.9,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5435",
              "epss": 0.00237,
              "percentile": 0.1487,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5435",
              "cwe": "CWE-787",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5435",
            "versionConstraint": "< 0:2.34-274.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-274.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "81f30677c0ddeeec",
        "name": "glibc-minimal-langpack",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5419",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5419",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5419",
            "epss": 0.00379,
            "percentile": 0.30598,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5419",
            "cwe": "CWE-208",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.12696499999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5419",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5419",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/security/cve/CVE-2026-5419",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467686",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13"
          ],
          "description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5419",
              "epss": 0.00379,
              "percentile": 0.30598,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5419",
              "cwe": "CWE-208",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5419",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-7039",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-7039",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-7039",
            "epss": 0.0037,
            "percentile": 0.29689,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-7039",
            "cwe": "CWE-22",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.12394999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-7039",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-7039",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2025-7039",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2392423",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
          ],
          "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-7039",
              "epss": 0.0037,
              "percentile": 0.29689,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-7039",
              "cwe": "CWE-22",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-7039",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-45446",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-45446",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. The implementations of AES-SIV (Advanced Encryption Standard - SIV) and AES-GCM-SIV (Advanced Encryption Standard - Galois/Counter Mode - SIV) incorrectly process authentication tags for empty messages. This vulnerability allows a remote attacker to forge empty messages with arbitrary Additional Authenticated Data (AAD) in applications that utilize these specific cipher modes within custom protocols and do not properly handle zero-length ciphertexts. This could lead to unauthorized data manipulation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-45446",
            "epss": 0.00363,
            "percentile": 0.28938,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-45446",
            "cwe": "CWE-325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.12160499999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-45446",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-45446",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/25b32cd9d41d2bc01b6abc425bb4baf2c2236fdc",
            "https://github.com/openssl/openssl/commit/71e2a5d263518cf5866043bd60ee4994d59e53a3",
            "https://github.com/openssl/openssl/commit/7fe3f33a3b3a4c487aa4dcdbc87057f66ffd2b85",
            "https://github.com/openssl/openssl/commit/daca0f48e4a69a2892a62262bad59e62a8a76598",
            "https://github.com/openssl/openssl/commit/eec5e9bf0d867333b8495e456f5235d225798a68",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV\n(RFC 8452) mishandle the authentication of AAD (Additional Authenticated\nData) with an empty ciphertext allowing a forgery of such messages.\n\nImpact summary: An attacker can forge empty messages with arbitrary AAD\nto the victim's application using these ciphers.\n\nAES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD\nmodes: they accept a key, nonce, optional AAD (bytes that are authenticated\nbut not encrypted), and plaintext, and produces ciphertext plus a 16-byte\ntag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only\nif the tag is verified succesfully.\n\nIn OpenSSL's provider implementation of these ciphers, the expected tag is\ncomputed only when decryption function is invoked with non-empty data.\nIf the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without\ninvocation of the ciphertext update, which can happen when the received\nciphertext length is zero, the tag is never recalculated and still holds its\nall-zeros value.\n\nWhen AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty\nciphertext, and all-zeros tag passes authentication under any key they do not\nknow, single-shot. When AES-SIV is used, for mounting the attack it's\nnecessary for the application to reuse the decryption context without\nresetting the key.\n\nAES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since\nOpenSSL 3.2.\n\nNo protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support\neither AES-GCM-SIV or AES-SIV. To mount an attack, the applications must\nimplement their own protocol and use the EVP interface. Also they must skip the\nciphertext update when a message with an empty ciphertext arrives.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as these algorithms are not FIPS approved and the affected code is\noutside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 4.8,
                "exploitabilityScore": 2.3,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-45446",
              "epss": 0.00363,
              "percentile": 0.28938,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-45446",
              "cwe": "CWE-325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-45446",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-45446",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-45446",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. The implementations of AES-SIV (Advanced Encryption Standard - SIV) and AES-GCM-SIV (Advanced Encryption Standard - Galois/Counter Mode - SIV) incorrectly process authentication tags for empty messages. This vulnerability allows a remote attacker to forge empty messages with arbitrary Additional Authenticated Data (AAD) in applications that utilize these specific cipher modes within custom protocols and do not properly handle zero-length ciphertexts. This could lead to unauthorized data manipulation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-45446",
            "epss": 0.00363,
            "percentile": 0.28938,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-45446",
            "cwe": "CWE-325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.12160499999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-45446",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-45446",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/25b32cd9d41d2bc01b6abc425bb4baf2c2236fdc",
            "https://github.com/openssl/openssl/commit/71e2a5d263518cf5866043bd60ee4994d59e53a3",
            "https://github.com/openssl/openssl/commit/7fe3f33a3b3a4c487aa4dcdbc87057f66ffd2b85",
            "https://github.com/openssl/openssl/commit/daca0f48e4a69a2892a62262bad59e62a8a76598",
            "https://github.com/openssl/openssl/commit/eec5e9bf0d867333b8495e456f5235d225798a68",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV\n(RFC 8452) mishandle the authentication of AAD (Additional Authenticated\nData) with an empty ciphertext allowing a forgery of such messages.\n\nImpact summary: An attacker can forge empty messages with arbitrary AAD\nto the victim's application using these ciphers.\n\nAES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD\nmodes: they accept a key, nonce, optional AAD (bytes that are authenticated\nbut not encrypted), and plaintext, and produces ciphertext plus a 16-byte\ntag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only\nif the tag is verified succesfully.\n\nIn OpenSSL's provider implementation of these ciphers, the expected tag is\ncomputed only when decryption function is invoked with non-empty data.\nIf the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without\ninvocation of the ciphertext update, which can happen when the received\nciphertext length is zero, the tag is never recalculated and still holds its\nall-zeros value.\n\nWhen AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty\nciphertext, and all-zeros tag passes authentication under any key they do not\nknow, single-shot. When AES-SIV is used, for mounting the attack it's\nnecessary for the application to reuse the decryption context without\nresetting the key.\n\nAES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since\nOpenSSL 3.2.\n\nNo protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support\neither AES-GCM-SIV or AES-SIV. To mount an attack, the applications must\nimplement their own protocol and use the EVP interface. Also they must skip the\nciphertext update when a message with an empty ciphertext arrives.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as these algorithms are not FIPS approved and the affected code is\noutside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 4.8,
                "exploitabilityScore": 2.3,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-45446",
              "epss": 0.00363,
              "percentile": 0.28938,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-45446",
              "cwe": "CWE-325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-45446",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-0992",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-0992",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 2.9,
              "exploitabilityScore": 1.5,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-0992",
            "epss": 0.0041,
            "percentile": 0.33603,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-0992",
            "cwe": "CWE-400",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.12095
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-0992",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-0992",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:7519",
            "https://access.redhat.com/security/cve/CVE-2026-0992",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2429975",
            "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019"
          ],
          "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-0992",
              "epss": 0.0041,
              "percentile": 0.33603,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-0992",
              "cwe": "CWE-400",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libxml2",
              "version": "0:2.9.13-14.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-0992",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a840257087cebda4",
        "name": "libxml2",
        "version": "2.9.13-14.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libxml2-2.9.13-14.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-5918",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-5918",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L",
            "metrics": {
              "baseScore": 3.9,
              "exploitabilityScore": 1.4,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-5918",
            "epss": 0.00341,
            "percentile": 0.26638,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-5918",
            "cwe": "CWE-125",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.11764499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-5918",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-5918",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2025-5918",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2370877",
            "https://github.com/libarchive/libarchive/pull/2584",
            "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
          ],
          "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H",
              "metrics": {
                "baseScore": 6.6,
                "exploitabilityScore": 1.4,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 3.9,
                "exploitabilityScore": 1.4,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-5918",
              "epss": 0.00341,
              "percentile": 0.26638,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-5918",
              "cwe": "CWE-125",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-5918",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-41989",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-41989",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in Libgcrypt. A remote attacker could exploit this vulnerability by sending crafted Elliptic Curve Diffie-Hellman (ECDH) ciphertext to the `gcry_pk_decrypt` function. This can lead to a heap-based buffer overflow, potentially causing a denial of service (DoS) condition.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-41989",
            "epss": 0.00182,
            "percentile": 0.08137,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-41989",
            "cwe": "CWE-787",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.11375
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-41989",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-41989",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://dev.gnupg.org/T8211",
            "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html",
            "https://www.openwall.com/lists/oss-security/2026/04/21/1",
            "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.",
          "cvss": [
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
              "metrics": {
                "baseScore": 6.7,
                "exploitabilityScore": 1.5,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-41989",
              "epss": 0.00182,
              "percentile": 0.08137,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-41989",
              "cwe": "CWE-787",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libgcrypt",
              "version": "0:1.10.0-11.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-41989",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "bdcb3bee3b1ed812",
        "name": "libgcrypt",
        "version": "1.10.0-11.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libgcrypt:libgcrypt:1.10.0-11.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libgcrypt:1.10.0-11.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=rhel-9.7&upstream=libgcrypt-1.10.0-11.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4438",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4438",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc's DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "metrics": {
              "baseScore": 4,
              "exploitabilityScore": 2.6,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4438",
            "epss": 0.00316,
            "percentile": 0.23977,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4438",
            "cwe": "CWE-20",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-4438",
            "cwe": "CWE-88",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-270.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-270.el9_8",
              "date": "2026-05-27",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20597",
            "link": "https://access.redhat.com/errata/RHSA-2026:20597"
          }
        ],
        "risk": 0.1106
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4438",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4438",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34015",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 5.4,
                "exploitabilityScore": 2.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4438",
              "epss": 0.00316,
              "percentile": 0.23977,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4438",
              "cwe": "CWE-20",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-4438",
              "cwe": "CWE-88",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "0:2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4438",
            "versionConstraint": "< 0:2.34-270.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-270.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "d41f8063e44e2263",
        "name": "glibc",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4438",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4438",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc's DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "metrics": {
              "baseScore": 4,
              "exploitabilityScore": 2.6,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4438",
            "epss": 0.00316,
            "percentile": 0.23977,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4438",
            "cwe": "CWE-20",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-4438",
            "cwe": "CWE-88",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-270.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-270.el9_8",
              "date": "2026-05-27",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20597",
            "link": "https://access.redhat.com/errata/RHSA-2026:20597"
          }
        ],
        "risk": 0.1106
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4438",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4438",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34015",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 5.4,
                "exploitabilityScore": 2.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4438",
              "epss": 0.00316,
              "percentile": 0.23977,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4438",
              "cwe": "CWE-20",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-4438",
              "cwe": "CWE-88",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4438",
            "versionConstraint": "< 0:2.34-270.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-270.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "1135b72e9fa314da",
        "name": "glibc-common",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_common:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-common:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_common:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-common@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4438",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4438",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc's DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "metrics": {
              "baseScore": 4,
              "exploitabilityScore": 2.6,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4438",
            "epss": 0.00316,
            "percentile": 0.23977,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4438",
            "cwe": "CWE-20",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-4438",
            "cwe": "CWE-88",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.34-270.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.34-270.el9_8",
              "date": "2026-05-27",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20597",
            "link": "https://access.redhat.com/errata/RHSA-2026:20597"
          }
        ],
        "risk": 0.1106
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4438",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4438",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34015",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 5.4,
                "exploitabilityScore": 2.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4438",
              "epss": 0.00316,
              "percentile": 0.23977,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4438",
              "cwe": "CWE-20",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-4438",
              "cwe": "CWE-88",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glibc",
              "version": "2.34-231.el9_7.10"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4438",
            "versionConstraint": "< 0:2.34-270.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.34-270.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "81f30677c0ddeeec",
        "name": "glibc-minimal-langpack",
        "version": "2.34-231.el9_7.10",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*",
          "cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-231.el9_7.10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-231.el9_7.10?arch=x86_64&distro=rhel-9.7&upstream=glibc-2.34-231.el9_7.10.src.rpm",
        "upstreams": [
          {
            "name": "glibc",
            "version": "2.34-231.el9_7.10"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-5278",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-5278",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "metrics": {
              "baseScore": 4.4,
              "exploitabilityScore": 1.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-5278",
            "epss": 0.00233,
            "percentile": 0.14394,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-5278",
            "cwe": "CWE-121",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:8.32-41.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:8.32-41.el9_8",
              "date": "2026-06-24",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:28911",
            "link": "https://access.redhat.com/errata/RHSA-2026:28911"
          }
        ],
        "risk": 0.10951000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-5278",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-5278",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:28911",
            "https://access.redhat.com/errata/RHSA-2026:33124",
            "https://access.redhat.com/errata/RHSA-2026:33313",
            "https://access.redhat.com/errata/RHSA-2026:33612",
            "https://access.redhat.com/errata/RHSA-2026:34102",
            "https://access.redhat.com/errata/RHSA-2026:39981",
            "https://access.redhat.com/errata/RHSA-2026:44481",
            "https://access.redhat.com/errata/RHSA-2026:46836",
            "https://access.redhat.com/security/cve/CVE-2025-5278",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2368764",
            "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633",
            "https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507",
            "http://www.openwall.com/lists/oss-security/2025/05/27/2",
            "http://www.openwall.com/lists/oss-security/2025/05/29/1",
            "http://www.openwall.com/lists/oss-security/2025/05/29/2",
            "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14",
            "https://security-tracker.debian.org/tracker/CVE-2025-5278"
          ],
          "description": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 4.4,
                "exploitabilityScore": 1.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-5278",
              "epss": 0.00233,
              "percentile": 0.14394,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-5278",
              "cwe": "CWE-121",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "coreutils",
              "version": "8.32-39.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-5278",
            "versionConstraint": "< 0:8.32-41.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:8.32-41.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "8ef168befafd7b27",
        "name": "coreutils-single",
        "version": "8.32-39.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+"
        ],
        "cpes": [
          "cpe:2.3:a:coreutils-single:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils-single:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils_single:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils_single:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/coreutils-single@8.32-39.el9?arch=x86_64&distro=rhel-9.7&upstream=coreutils-8.32-39.el9.src.rpm",
        "upstreams": [
          {
            "name": "coreutils",
            "version": "8.32-39.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34181",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-34181",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. This vulnerability allows a remote attacker to forge PKCS#12 (Public-Key Cryptography Standards #12) files that use Password-Based Message Authentication Code 1 (PBMAC1) with short HMAC (Hash-based Message Authentication Code) keys. This can lead to a service accepting attacker-controlled certificates and private keys with a 1 in 256 probability, potentially enabling impersonation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 6.3,
              "exploitabilityScore": 1.1,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34181",
            "epss": 0.00235,
            "percentile": 0.1467,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34181",
            "cwe": "CWE-354",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.109275
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34181",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34181",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/0300eb9ddce7a0895bf301a4b0c03a9da2313a0f",
            "https://github.com/openssl/openssl/commit/79eb76a937e474bb7610a0a3dc57131dc8dc6610",
            "https://github.com/openssl/openssl/commit/85dcbb3abaa4878af5c8fbbe11bce708fcf984a7",
            "https://github.com/openssl/openssl/commit/ec36f2417c4ddd8cabce4b4a60a3d7a7365f2d81",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue Summary: The PKCS#12 file processing fails to perform sufficient input\nvalidation for files that use Password-Based Message Authentication Code 1\n(PBMAC1) integrity mechanism allowing a certificate and private key forgery.\n\nImpact Summary: An attacker impersonating a user can cause a service reading\nPKCS#12 files to accept forged certificates and private keys with a 1 in 256\nprobability.\n\nIf a service accepting PKCS#12 files is using passwords for authenticating\nthe received files, the attacker can create unencrypted PKCS#12 files that\nuse PBMAC1 authentication that specifies an HMAC key of only one byte, allowing\nthem to craft a file that will be accepted with a 1 in 256 probability.\nThat would then cause the service to accept a certificate and private key\ncontrolled by the attacker.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.4,
                "exploitabilityScore": 2.3,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34181",
              "epss": 0.00235,
              "percentile": 0.1467,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34181",
              "cwe": "CWE-354",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34181",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34181",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-34181",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. This vulnerability allows a remote attacker to forge PKCS#12 (Public-Key Cryptography Standards #12) files that use Password-Based Message Authentication Code 1 (PBMAC1) with short HMAC (Hash-based Message Authentication Code) keys. This can lead to a service accepting attacker-controlled certificates and private keys with a 1 in 256 probability, potentially enabling impersonation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 6.3,
              "exploitabilityScore": 1.1,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34181",
            "epss": 0.00235,
            "percentile": 0.1467,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34181",
            "cwe": "CWE-354",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:3.5.5-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:3.5.5-4.el9_8",
              "date": "2026-06-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:25239",
            "link": "https://access.redhat.com/errata/RHSA-2026:25239"
          }
        ],
        "risk": 0.109275
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34181",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34181",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/0300eb9ddce7a0895bf301a4b0c03a9da2313a0f",
            "https://github.com/openssl/openssl/commit/79eb76a937e474bb7610a0a3dc57131dc8dc6610",
            "https://github.com/openssl/openssl/commit/85dcbb3abaa4878af5c8fbbe11bce708fcf984a7",
            "https://github.com/openssl/openssl/commit/ec36f2417c4ddd8cabce4b4a60a3d7a7365f2d81",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue Summary: The PKCS#12 file processing fails to perform sufficient input\nvalidation for files that use Password-Based Message Authentication Code 1\n(PBMAC1) integrity mechanism allowing a certificate and private key forgery.\n\nImpact Summary: An attacker impersonating a user can cause a service reading\nPKCS#12 files to accept forged certificates and private keys with a 1 in 256\nprobability.\n\nIf a service accepting PKCS#12 files is using passwords for authenticating\nthe received files, the attacker can create unencrypted PKCS#12 files that\nuse PBMAC1 authentication that specifies an HMAC key of only one byte, allowing\nthem to craft a file that will be accepted with a 1 in 256 probability.\nThat would then cause the service to accept a certificate and private key\ncontrolled by the attacker.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.4,
                "exploitabilityScore": 2.3,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34181",
              "epss": 0.00235,
              "percentile": 0.1467,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34181",
              "cwe": "CWE-354",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34181",
            "versionConstraint": "< 1:3.5.5-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "1:3.5.5-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-1757",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-1757",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.2,
              "exploitabilityScore": 2.6,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-1757",
            "epss": 0.00194,
            "percentile": 0.09461,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-1757",
            "cwe": "CWE-401",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.10864000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-1757",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-1757",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:7519",
            "https://access.redhat.com/security/cve/CVE-2026-1757",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2435940",
            "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009"
          ],
          "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.2,
                "exploitabilityScore": 2.6,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-1757",
              "epss": 0.00194,
              "percentile": 0.09461,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-1757",
              "cwe": "CWE-401",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libxml2",
              "version": "0:2.9.13-14.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-1757",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a840257087cebda4",
        "name": "libxml2",
        "version": "2.9.13-14.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libxml2-2.9.13-14.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-54369",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-54369",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in the `acl` package, specifically within its `libacl` pathname-based functions. A local attacker could exploit this vulnerability by using a symbolic link to replace a pathname component. This could allow the attacker to redirect access control list (ACL) read or write operations to arbitrary files or directories, leading to unauthorized manipulation of ACLs and ultimately local privilege escalation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 7.1,
              "exploitabilityScore": 1.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-54369",
            "epss": 0.00147,
            "percentile": 0.04405,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-54369",
            "cwe": "CWE-59",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-54369",
            "cwe": "CWE-59",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.4.0-1.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.4.0-1.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42736",
            "link": "https://access.redhat.com/errata/RHSA-2026:42736"
          }
        ],
        "risk": 0.10731
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-54369",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-54369",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5",
            "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1",
            "https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions",
            "https://access.redhat.com/errata/RHSA-2026:34351",
            "https://access.redhat.com/errata/RHSA-2026:42736",
            "https://access.redhat.com/errata/RHSA-2026:42739",
            "https://access.redhat.com/errata/RHSA-2026:43420",
            "https://access.redhat.com/errata/RHSA-2026:44481",
            "https://access.redhat.com/errata/RHSA-2026:46836",
            "https://access.redhat.com/security/cve/CVE-2026-54369",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2490277",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"
          ],
          "description": "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 1.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 8.4
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 1.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-54369",
              "epss": 0.00147,
              "percentile": 0.04405,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-54369",
              "cwe": "CWE-59",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-54369",
              "cwe": "CWE-59",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "acl",
              "version": "0:2.3.1-4.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-54369",
            "versionConstraint": "< 0:2.4.0-1.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.4.0-1.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "2cbc02d73c9fa253",
        "name": "acl",
        "version": "2.3.1-4.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:acl:2.3.1-4.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:acl:acl:2.3.1-4.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/acl@2.3.1-4.el9?arch=x86_64&distro=rhel-9.7&upstream=acl-2.3.1-4.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-54369",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-54369",
        "namespace": "redhat:distro:redhat:9",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in the `acl` package, specifically within its `libacl` pathname-based functions. A local attacker could exploit this vulnerability by using a symbolic link to replace a pathname component. This could allow the attacker to redirect access control list (ACL) read or write operations to arbitrary files or directories, leading to unauthorized manipulation of ACLs and ultimately local privilege escalation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 7.1,
              "exploitabilityScore": 1.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-54369",
            "epss": 0.00147,
            "percentile": 0.04405,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-54369",
            "cwe": "CWE-59",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-54369",
            "cwe": "CWE-59",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.4.0-1.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.4.0-1.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42736",
            "link": "https://access.redhat.com/errata/RHSA-2026:42736"
          }
        ],
        "risk": 0.10731
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-54369",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-54369",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5",
            "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1",
            "https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions",
            "https://access.redhat.com/errata/RHSA-2026:34351",
            "https://access.redhat.com/errata/RHSA-2026:42736",
            "https://access.redhat.com/errata/RHSA-2026:42739",
            "https://access.redhat.com/errata/RHSA-2026:43420",
            "https://access.redhat.com/errata/RHSA-2026:44481",
            "https://access.redhat.com/errata/RHSA-2026:46836",
            "https://access.redhat.com/security/cve/CVE-2026-54369",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2490277",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"
          ],
          "description": "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 1.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 8.4
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 1.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-54369",
              "epss": 0.00147,
              "percentile": 0.04405,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-54369",
              "cwe": "CWE-59",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-54369",
              "cwe": "CWE-59",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "acl",
              "version": "2.3.1-4.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-54369",
            "versionConstraint": "< 0:2.4.0-1.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.4.0-1.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "efaae8c603855dcd",
        "name": "libacl",
        "version": "2.3.1-4.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libacl:libacl:2.3.1-4.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libacl:2.3.1-4.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64&distro=rhel-9.7&upstream=acl-2.3.1-4.el9.src.rpm",
        "upstreams": [
          {
            "name": "acl",
            "version": "2.3.1-4.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-31789",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-31789",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. This vulnerability, a heap buffer overflow, affects 32-bit systems when processing an unusually large X.509 certificate. If an application or service attempts to print or log such a specially crafted certificate, it could lead to a system crash or potentially allow an attacker to execute arbitrary code. This issue is considered low severity due to the specific conditions required for exploitation, including the need for an extremely large certificate and a 32-bit operating environment.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H",
            "metrics": {
              "baseScore": 5.8,
              "exploitabilityScore": 1.1,
              "impactScore": 4.8
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-31789",
            "epss": 0.00243,
            "percentile": 0.15665,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-31789",
            "cwe": "CWE-787",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.10691999999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-31789",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-31789",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde",
            "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf",
            "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49",
            "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9",
            "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H",
              "metrics": {
                "baseScore": 5.8,
                "exploitabilityScore": 1.1,
                "impactScore": 4.8
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-31789",
              "epss": 0.00243,
              "percentile": 0.15665,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-31789",
              "cwe": "CWE-787",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "1:3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-31789",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "019f13958fa4dc68",
        "name": "openssl",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-31789",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-31789",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in OpenSSL. This vulnerability, a heap buffer overflow, affects 32-bit systems when processing an unusually large X.509 certificate. If an application or service attempts to print or log such a specially crafted certificate, it could lead to a system crash or potentially allow an attacker to execute arbitrary code. This issue is considered low severity due to the specific conditions required for exploitation, including the need for an extremely large certificate and a 32-bit operating environment.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H",
            "metrics": {
              "baseScore": 5.8,
              "exploitabilityScore": 1.1,
              "impactScore": 4.8
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-31789",
            "epss": 0.00243,
            "percentile": 0.15665,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-31789",
            "cwe": "CWE-787",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.10691999999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-31789",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-31789",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde",
            "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf",
            "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49",
            "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9",
            "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H",
              "metrics": {
                "baseScore": 5.8,
                "exploitabilityScore": 1.1,
                "impactScore": 4.8
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-31789",
              "epss": 0.00243,
              "percentile": 0.15665,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-31789",
              "cwe": "CWE-787",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openssl",
              "version": "3.5.1-7.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-31789",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "15b6910272a6e502",
        "name": "openssl-libs",
        "version": "1:3.5.1-7.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:openssl:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl-libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openssl_libs:1\\:3.5.1-7.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openssl-libs@3.5.1-7.el9_7?arch=x86_64&distro=rhel-9.7&epoch=1&upstream=openssl-3.5.1-7.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "openssl",
            "version": "3.5.1-7.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": 1,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-1632",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-1632",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in the bsdunzip utility of libarchive. In affected versions, a specially crafted file may trigger a null pointer dereference. This issue can lead to an application crash or other unexpected behavior. This bug does not compromise the integrity or availability of the base system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.3,
              "exploitabilityScore": 1.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-1632",
            "epss": 0.00335,
            "percentile": 0.26074,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-1632",
            "cwe": "CWE-404",
            "source": "cna@vuldb.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2025-1632",
            "cwe": "CWE-476",
            "source": "cna@vuldb.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2025-1632",
            "cwe": "CWE-476",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.10552499999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-1632",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-1632",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc",
            "https://vuldb.com/?ctiid.296619",
            "https://vuldb.com/?id.296619",
            "https://vuldb.com/?submit.496460"
          ],
          "description": "A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cna@vuldb.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 4.8
              },
              "vendorMetadata": {}
            },
            {
              "source": "cna@vuldb.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 3.3,
                "exploitabilityScore": 1.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "cna@vuldb.com",
              "type": "Secondary",
              "version": "2.0",
              "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 1.7,
                "exploitabilityScore": 3.2,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-1632",
              "epss": 0.00335,
              "percentile": 0.26074,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-1632",
              "cwe": "CWE-404",
              "source": "cna@vuldb.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2025-1632",
              "cwe": "CWE-476",
              "source": "cna@vuldb.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2025-1632",
              "cwe": "CWE-476",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-1632",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-58055",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-58055",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw in nghttp2's nghttpx proxy allows a remote attacker to perform HTTP request smuggling and cross-client response-queue poisoning. This occurs because the proxy ambiguously forwards HTTP/1.1 Upgrade requests that contain a Content-Length header to reusable keep-alive backend connections.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 5.4,
              "exploitabilityScore": 2.3,
              "impactScore": 2.8
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-58055",
            "epss": 0.00202,
            "percentile": 0.10438,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-58055",
            "cwe": "CWE-444",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.10504000000000002
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-58055",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-58055",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc",
            "https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e",
            "https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"
          ],
          "description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
          "cvss": [
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 6.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 5.4,
                "exploitabilityScore": 2.3,
                "impactScore": 2.8
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-58055",
              "epss": 0.00202,
              "percentile": 0.10438,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-58055",
              "cwe": "CWE-444",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "nghttp2",
              "version": "1.43.0-6.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-58055",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7a79c42db6e2de7e",
        "name": "libnghttp2",
        "version": "1.43.0-6.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libnghttp2:libnghttp2:1.43.0-6.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libnghttp2:1.43.0-6.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=nghttp2-1.43.0-6.el9_7.1.src.rpm",
        "upstreams": [
          {
            "name": "nghttp2",
            "version": "1.43.0-6.el9_7.1"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-30571",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2023-30571",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A vulnerability was found in libarchive. This issue can cause a race condition in a multi-threaded use of archive_write_disk_header() on posix based systems, which could allow implicit directory creation with permissions 777, without sticky bit, which means any low privileged user on the system can delete and rename files inside those directories.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.1,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2023-30571",
            "epss": 0.00192,
            "percentile": 0.09231,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2023-30571",
            "cwe": "CWE-362",
            "source": "nvd@nist.gov",
            "type": "Primary"
          },
          {
            "cve": "CVE-2023-30571",
            "cwe": "CWE-362",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.09888
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-30571",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-30571",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/libarchive/libarchive/issues/1876",
            "https://groups.google.com/g/libarchive-announce"
          ],
          "description": "Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.1,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 3.9,
                "exploitabilityScore": 0.9,
                "impactScore": 2.8
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-30571",
              "epss": 0.00192,
              "percentile": 0.09231,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2023-30571",
              "cwe": "CWE-362",
              "source": "nvd@nist.gov",
              "type": "Primary"
            },
            {
              "cve": "CVE-2023-30571",
              "cwe": "CWE-362",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-30571",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-15588",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-15588",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.9,
              "impactScore": 3.4
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-15588",
            "epss": 0.00192,
            "percentile": 0.09149,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-15588",
            "cwe": "CWE-770",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.09888
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-15588",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-15588",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:39985",
            "https://access.redhat.com/errata/RHSA-2026:40485",
            "https://access.redhat.com/errata/RHSA-2026:42329",
            "https://access.redhat.com/security/cve/CVE-2026-15588",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2499675",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3985"
          ],
          "description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.9,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-15588",
              "epss": 0.00192,
              "percentile": 0.09149,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-15588",
              "cwe": "CWE-770",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-15588",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6276",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-6276",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom `Host:` header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new `Host:` header. This can lead to libcurl incorrectly sending cookies intended for the first host to the second host, resulting in a cookie leak. This issue is categorized as an Origin Validation Error (CWE-346). Exploitation typically requires specific debugging configurations.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6276",
            "epss": 0.00295,
            "percentile": 0.21729,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6276",
            "cwe": "CWE-319",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.098825
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6276",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-6276.html",
            "https://curl.se/docs/CVE-2026-6276.json",
            "https://hackerone.com/reports/3671818",
            "http://www.openwall.com/lists/oss-security/2026/04/29/13"
          ],
          "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6276",
              "epss": 0.00295,
              "percentile": 0.21729,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6276",
              "cwe": "CWE-319",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6276",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6276",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-6276",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom `Host:` header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new `Host:` header. This can lead to libcurl incorrectly sending cookies intended for the first host to the second host, resulting in a cookie leak. This issue is categorized as an Origin Validation Error (CWE-346). Exploitation typically requires specific debugging configurations.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6276",
            "epss": 0.00295,
            "percentile": 0.21729,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6276",
            "cwe": "CWE-319",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.098825
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6276",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-6276.html",
            "https://curl.se/docs/CVE-2026-6276.json",
            "https://hackerone.com/reports/3671818",
            "http://www.openwall.com/lists/oss-security/2026/04/29/13"
          ],
          "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6276",
              "epss": 0.00295,
              "percentile": 0.21729,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6276",
              "cwe": "CWE-319",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6276",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-32777",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-32777",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted Document Type Definition (DTD) content. This could lead to an infinite loop during parsing, resulting in a Denial of Service (DoS) for the application using libexpat.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 4,
              "exploitabilityScore": 2.6,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-32777",
            "epss": 0.00216,
            "percentile": 0.12211,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-32777",
            "cwe": "CWE-835",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0972
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-32777",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-32777",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/libexpat/libexpat/issues/1161",
            "https://github.com/libexpat/libexpat/pull/1159",
            "https://github.com/libexpat/libexpat/pull/1162",
            "https://issues.oss-fuzz.com/issues/486993411",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 4,
                "exploitabilityScore": 2.6,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-32777",
              "epss": 0.00216,
              "percentile": 0.12211,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-32777",
              "cwe": "CWE-835",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-32777",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-70873",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-70873",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in SQLite. This information disclosure vulnerability exists within the zipfile extension, specifically in the zipfileInflate function. A remote attacker could exploit this by providing a specially crafted ZIP file. Successful exploitation could lead to the disclosure of sensitive heap memory information.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 3.3,
              "exploitabilityScore": 1.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-70873",
            "epss": 0.00301,
            "percentile": 0.22364,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-70873",
            "cwe": "CWE-244",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.09481499999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-70873",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-70873",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054",
            "https://sqlite.org/forum/forumpost/761eac3c82",
            "https://sqlite.org/src/info/3d459f1fb1bd1b5e"
          ],
          "description": "An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-70873",
              "epss": 0.00301,
              "percentile": 0.22364,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-70873",
              "cwe": "CWE-244",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "sqlite",
              "version": "3.34.1-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-70873",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "1bd197aae1b6fd3b",
        "name": "sqlite-libs",
        "version": "3.34.1-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/sqlite-libs@3.34.1-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=sqlite-3.34.1-9.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "sqlite",
            "version": "3.34.1-9.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-32776",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-32776",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted XML content with empty external parameter entities. This could lead to a NULL pointer dereference, causing the application to crash and resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.2,
              "exploitabilityScore": 2.6,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-32776",
            "epss": 0.00164,
            "percentile": 0.06029,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-32776",
            "cwe": "CWE-476",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.09184
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-32776",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-32776",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/libexpat/libexpat/pull/1158",
            "https://github.com/libexpat/libexpat/pull/1159",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 4,
                "exploitabilityScore": 2.6,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-32776",
              "epss": 0.00164,
              "percentile": 0.06029,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-32776",
              "cwe": "CWE-476",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-32776",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42014",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42014",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
            "metrics": {
              "baseScore": 6.6,
              "exploitabilityScore": 1.9,
              "impactScore": 4.8
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42014",
            "epss": 0.0015,
            "percentile": 0.04666,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42014",
            "cwe": "CWE-825",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:3.8.10-4.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:3.8.10-4.el9_8",
              "date": "2026-06-03",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:20612",
            "link": "https://access.redhat.com/errata/RHSA-2026:20612"
          }
        ],
        "risk": 0.087
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42014",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42014",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-42014",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467451",
            "https://gitlab.com/gnutls/gnutls/-/issues/1766",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-9"
          ],
          "description": "A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
              "metrics": {
                "baseScore": 6.6,
                "exploitabilityScore": 1.9,
                "impactScore": 4.8
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42014",
              "epss": 0.0015,
              "percentile": 0.04666,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42014",
              "cwe": "CWE-825",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnutls",
              "version": "0:3.8.3-10.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42014",
            "versionConstraint": "< 0:3.8.10-4.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:3.8.10-4.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "72401aee18e97ea8",
        "name": "gnutls",
        "version": "3.8.3-10.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:gnutls:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnutls:3.8.3-10.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnutls@3.8.3-10.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnutls-3.8.3-10.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-32778",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-32778",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libexpat. This vulnerability allows an attacker to trigger a NULL pointer dereference in the `setContext` function. This occurs when the system attempts to retry an operation after an out-of-memory condition, which can lead to a Denial of Service (DoS) for the affected application.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.1,
              "exploitabilityScore": 1.5,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-32778",
            "epss": 0.00171,
            "percentile": 0.0674,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-32778",
            "cwe": "CWE-476",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.08635499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-32778",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-32778",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/libexpat/libexpat/pull/1159",
            "https://github.com/libexpat/libexpat/pull/1163",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-32778",
              "epss": 0.00171,
              "percentile": 0.0674,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-32778",
              "cwe": "CWE-476",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-32778",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5745",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5745",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 1.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5745",
            "epss": 0.00163,
            "percentile": 0.05909,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5745",
            "cwe": "CWE-476",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.085575
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5745",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5745",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:8944",
            "https://access.redhat.com/security/cve/CVE-2026-5745",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2455921"
          ],
          "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5745",
              "epss": 0.00163,
              "percentile": 0.05909,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5745",
              "cwe": "CWE-476",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5745",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4105",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4105",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 6.7,
              "exploitabilityScore": 0.8,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4105",
            "epss": 0.00142,
            "percentile": 0.03917,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4105",
            "cwe": "CWE-284",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.08306999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4105",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4105",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:7299",
            "https://access.redhat.com/security/cve/CVE-2026-4105",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2447262",
            "https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
          ],
          "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 6.7,
                "exploitabilityScore": 0.8,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4105",
              "epss": 0.00142,
              "percentile": 0.03917,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4105",
              "cwe": "CWE-284",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "systemd",
              "version": "0:252-55.el9_7.8"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4105",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "df6f29af38d52836",
        "name": "systemd",
        "version": "252-55.el9_7.8",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and MIT and GPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:systemd:systemd:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd:252-55.el9_7.8:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/systemd@252-55.el9_7.8?arch=x86_64&distro=rhel-9.7&upstream=systemd-252-55.el9_7.8.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4105",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4105",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 6.7,
              "exploitabilityScore": 0.8,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4105",
            "epss": 0.00142,
            "percentile": 0.03917,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4105",
            "cwe": "CWE-284",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.08306999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4105",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4105",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:7299",
            "https://access.redhat.com/security/cve/CVE-2026-4105",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2447262",
            "https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
          ],
          "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 6.7,
                "exploitabilityScore": 0.8,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4105",
              "epss": 0.00142,
              "percentile": 0.03917,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4105",
              "cwe": "CWE-284",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "systemd",
              "version": "252-55.el9_7.8"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4105",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "225930218e202c55",
        "name": "systemd-libs",
        "version": "252-55.el9_7.8",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and MIT"
        ],
        "cpes": [
          "cpe:2.3:a:systemd-libs:systemd-libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd-libs:systemd_libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_libs:systemd-libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_libs:systemd_libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd-libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd_libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd-libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd_libs:252-55.el9_7.8:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/systemd-libs@252-55.el9_7.8?arch=x86_64&distro=rhel-9.7&upstream=systemd-252-55.el9_7.8.src.rpm",
        "upstreams": [
          {
            "name": "systemd",
            "version": "252-55.el9_7.8"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4105",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4105",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 6.7,
              "exploitabilityScore": 0.8,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4105",
            "epss": 0.00142,
            "percentile": 0.03917,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4105",
            "cwe": "CWE-284",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.08306999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4105",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4105",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:7299",
            "https://access.redhat.com/security/cve/CVE-2026-4105",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2447262",
            "https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
          ],
          "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 6.7,
                "exploitabilityScore": 0.8,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4105",
              "epss": 0.00142,
              "percentile": 0.03917,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4105",
              "cwe": "CWE-284",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "systemd",
              "version": "252-55.el9_7.8"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4105",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "3d0ecc245e8e9fc2",
        "name": "systemd-pam",
        "version": "252-55.el9_7.8",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and MIT and GPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:systemd-pam:systemd-pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd-pam:systemd_pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_pam:systemd-pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_pam:systemd_pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd-pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd_pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd-pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd_pam:252-55.el9_7.8:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/systemd-pam@252-55.el9_7.8?arch=x86_64&distro=rhel-9.7&upstream=systemd-252-55.el9_7.8.src.rpm",
        "upstreams": [
          {
            "name": "systemd",
            "version": "252-55.el9_7.8"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4105",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-4105",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 6.7,
              "exploitabilityScore": 0.8,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4105",
            "epss": 0.00142,
            "percentile": 0.03917,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4105",
            "cwe": "CWE-284",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.08306999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4105",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4105",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:7299",
            "https://access.redhat.com/security/cve/CVE-2026-4105",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2447262",
            "https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
          ],
          "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 6.7,
                "exploitabilityScore": 0.8,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4105",
              "epss": 0.00142,
              "percentile": 0.03917,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4105",
              "cwe": "CWE-284",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "systemd",
              "version": "252-55.el9_7.8"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4105",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "127de483e2efb7b9",
        "name": "systemd-rpm-macros",
        "version": "252-55.el9_7.8",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and MIT and GPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:systemd-rpm-macros:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd-rpm-macros:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_rpm_macros:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_rpm_macros:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd-rpm:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd-rpm:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_rpm:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_rpm:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/systemd-rpm-macros@252-55.el9_7.8?arch=noarch&distro=rhel-9.7&upstream=systemd-252-55.el9_7.8.src.rpm",
        "upstreams": [
          {
            "name": "systemd",
            "version": "252-55.el9_7.8"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "noarch"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-60753",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-60753",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A vulnerability in apply_substitution() function in libarchive's bsdtar allows crafted -s substitution rules to repeatedly match a zero-length substring and append replacements without advancing the input pointer. When the rule uses the global /g flag (or an explicitly empty pattern), this leads to unbounded output allocation and eventual process OOM (Denial of Service). Upgrade to libarchive 3.8.1 or apply a patch that prevents zero-length match loops or rejects empty patterns.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 1.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-60753",
            "epss": 0.00157,
            "percentile": 0.05321,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-60753",
            "cwe": "CWE-400",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2025-60753",
            "cwe": "CWE-835",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.082425
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-60753",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-60753",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753",
            "https://github.com/libarchive/libarchive/issues/2725"
          ],
          "description": "An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-60753",
              "epss": 0.00157,
              "percentile": 0.05321,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-60753",
              "cwe": "CWE-400",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2025-60753",
              "cwe": "CWE-835",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-60753",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-16118",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-16118",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
            "metrics": {
              "baseScore": 7.1,
              "exploitabilityScore": 1.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-16118",
            "epss": 0.00134,
            "percentile": 0.03321,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-16118",
            "cwe": "CWE-122",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.08107
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-16118",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-16118",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-16118",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2501732",
            "https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41"
          ],
          "description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 1.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-16118",
              "epss": 0.00134,
              "percentile": 0.03321,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-16118",
              "cwe": "CWE-122",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-16118",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5958",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-5958",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A Time-of-Check Time-of-Use (TOCTOU) race condition was found in GNU sed. When the -i (in-place) and --follow-symlinks options are used together, sed resolves the symlink but reopens the path for writing. An attacker with write access to the directory containing the symlink can swap it between the check and the open operations. If a privileged user executes sed in this manner on a path influenced by the attacker, it can lead to arbitrary file overwrites and potential privilege escalation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "metrics": {
              "baseScore": 6.3,
              "exploitabilityScore": 1.1,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5958",
            "epss": 0.00142,
            "percentile": 0.0393,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5958",
            "cwe": "CWE-367",
            "source": "cvd@cert.pl",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.08023
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5958",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5958",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://cert.pl/en/posts/2026/04/CVE-2026-5958",
            "https://www.gnu.org/software/sed/",
            "http://www.openwall.com/lists/oss-security/2026/05/13/1"
          ],
          "description": "When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores the resolved path for determining when output is written,\n2. opens the original symlink path (not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1. This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\n\n\nThis issue was fixed in version 4.10.",
          "cvss": [
            {
              "source": "cvd@cert.pl",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 2.1
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5958",
              "epss": 0.00142,
              "percentile": 0.0393,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5958",
              "cwe": "CWE-367",
              "source": "cvd@cert.pl",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "sed",
              "version": "0:4.8-9.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5958",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "e21cb9e7dda039e1",
        "name": "sed",
        "version": "4.8-9.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:sed:4.8-9.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:sed:sed:4.8-9.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/sed@4.8-9.el9?arch=x86_64&distro=rhel-9.7&upstream=sed-4.8-9.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-56406",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-56406",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libexpat. An integer overflow vulnerability exists in the `XML_ParseBuffer` function due to a missing check. This flaw could allow an attacker to cause memory corruption, potentially leading to arbitrary code execution, information disclosure, or a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "metrics": {
              "baseScore": 6.9,
              "exploitabilityScore": 1.5,
              "impactScore": 5.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-56406",
            "epss": 0.00134,
            "percentile": 0.03288,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-56406",
            "cwe": "CWE-190",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.07973000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-56406",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-56406",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/libexpat/libexpat/pull/1255"
          ],
          "description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
          "cvss": [
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
              "metrics": {
                "baseScore": 6.9,
                "exploitabilityScore": 1.5,
                "impactScore": 5.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-56406",
              "epss": 0.00134,
              "percentile": 0.03288,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-56406",
              "cwe": "CWE-190",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-56406",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-5915",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-5915",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H",
            "metrics": {
              "baseScore": 6.6,
              "exploitabilityScore": 1.4,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-5915",
            "epss": 0.00163,
            "percentile": 0.05939,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-5915",
            "cwe": "CWE-122",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.07823999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-5915",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-5915",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2025-5915",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2370865",
            "https://github.com/libarchive/libarchive/pull/2599",
            "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
          ],
          "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H",
              "metrics": {
                "baseScore": 6.6,
                "exploitabilityScore": 1.4,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H",
              "metrics": {
                "baseScore": 6.6,
                "exploitabilityScore": 1.4,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-5915",
              "epss": 0.00163,
              "percentile": 0.05939,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-5915",
              "cwe": "CWE-122",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-5915",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-29111",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-29111",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 7.8,
              "exploitabilityScore": 1.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-29111",
            "epss": 0.00121,
            "percentile": 0.02275,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-29111",
            "cwe": "CWE-269",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:252-55.el9_7.9"
          ],
          "state": "fixed"
        },
        "advisories": [
          {
            "id": "RHSA-2026:13677",
            "link": "https://access.redhat.com/errata/RHSA-2026:13677"
          }
        ],
        "risk": 0.07744
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-29111",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-29111",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a",
            "https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6",
            "https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412",
            "https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd",
            "https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f",
            "https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f",
            "https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69",
            "https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6",
            "https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c",
            "https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8",
            "https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764"
          ],
          "description": "systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.",
          "cvss": [
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-29111",
              "epss": 0.00121,
              "percentile": 0.02275,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-29111",
              "cwe": "CWE-269",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "systemd",
              "version": "0:252-55.el9_7.8"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-29111",
            "versionConstraint": "< 0:252-55.el9_7.9 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:252-55.el9_7.9"
          }
        }
      ],
      "artifact": {
        "id": "df6f29af38d52836",
        "name": "systemd",
        "version": "252-55.el9_7.8",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and MIT and GPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:systemd:systemd:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd:252-55.el9_7.8:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/systemd@252-55.el9_7.8?arch=x86_64&distro=rhel-9.7&upstream=systemd-252-55.el9_7.8.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-29111",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-29111",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 7.8,
              "exploitabilityScore": 1.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-29111",
            "epss": 0.00121,
            "percentile": 0.02275,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-29111",
            "cwe": "CWE-269",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:252-55.el9_7.9"
          ],
          "state": "fixed"
        },
        "advisories": [
          {
            "id": "RHSA-2026:13677",
            "link": "https://access.redhat.com/errata/RHSA-2026:13677"
          }
        ],
        "risk": 0.07744
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-29111",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-29111",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a",
            "https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6",
            "https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412",
            "https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd",
            "https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f",
            "https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f",
            "https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69",
            "https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6",
            "https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c",
            "https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8",
            "https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764"
          ],
          "description": "systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.",
          "cvss": [
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-29111",
              "epss": 0.00121,
              "percentile": 0.02275,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-29111",
              "cwe": "CWE-269",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "systemd",
              "version": "252-55.el9_7.8"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-29111",
            "versionConstraint": "< 0:252-55.el9_7.9 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:252-55.el9_7.9"
          }
        }
      ],
      "artifact": {
        "id": "225930218e202c55",
        "name": "systemd-libs",
        "version": "252-55.el9_7.8",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and MIT"
        ],
        "cpes": [
          "cpe:2.3:a:systemd-libs:systemd-libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd-libs:systemd_libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_libs:systemd-libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_libs:systemd_libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd-libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd_libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd-libs:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd_libs:252-55.el9_7.8:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/systemd-libs@252-55.el9_7.8?arch=x86_64&distro=rhel-9.7&upstream=systemd-252-55.el9_7.8.src.rpm",
        "upstreams": [
          {
            "name": "systemd",
            "version": "252-55.el9_7.8"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-29111",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-29111",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 7.8,
              "exploitabilityScore": 1.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-29111",
            "epss": 0.00121,
            "percentile": 0.02275,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-29111",
            "cwe": "CWE-269",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:252-55.el9_7.9"
          ],
          "state": "fixed"
        },
        "advisories": [
          {
            "id": "RHSA-2026:13677",
            "link": "https://access.redhat.com/errata/RHSA-2026:13677"
          }
        ],
        "risk": 0.07744
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-29111",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-29111",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a",
            "https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6",
            "https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412",
            "https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd",
            "https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f",
            "https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f",
            "https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69",
            "https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6",
            "https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c",
            "https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8",
            "https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764"
          ],
          "description": "systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.",
          "cvss": [
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-29111",
              "epss": 0.00121,
              "percentile": 0.02275,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-29111",
              "cwe": "CWE-269",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "systemd",
              "version": "252-55.el9_7.8"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-29111",
            "versionConstraint": "< 0:252-55.el9_7.9 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:252-55.el9_7.9"
          }
        }
      ],
      "artifact": {
        "id": "3d0ecc245e8e9fc2",
        "name": "systemd-pam",
        "version": "252-55.el9_7.8",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and MIT and GPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:systemd-pam:systemd-pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd-pam:systemd_pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_pam:systemd-pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_pam:systemd_pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd-pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd_pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd-pam:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd_pam:252-55.el9_7.8:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/systemd-pam@252-55.el9_7.8?arch=x86_64&distro=rhel-9.7&upstream=systemd-252-55.el9_7.8.src.rpm",
        "upstreams": [
          {
            "name": "systemd",
            "version": "252-55.el9_7.8"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-29111",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-29111",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 7.8,
              "exploitabilityScore": 1.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-29111",
            "epss": 0.00121,
            "percentile": 0.02275,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-29111",
            "cwe": "CWE-269",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:252-55.el9_7.9"
          ],
          "state": "fixed"
        },
        "advisories": [
          {
            "id": "RHSA-2026:13677",
            "link": "https://access.redhat.com/errata/RHSA-2026:13677"
          }
        ],
        "risk": 0.07744
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-29111",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-29111",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a",
            "https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6",
            "https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412",
            "https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd",
            "https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f",
            "https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f",
            "https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69",
            "https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6",
            "https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c",
            "https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8",
            "https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764"
          ],
          "description": "systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.",
          "cvss": [
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-29111",
              "epss": 0.00121,
              "percentile": 0.02275,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-29111",
              "cwe": "CWE-269",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "systemd",
              "version": "252-55.el9_7.8"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-29111",
            "versionConstraint": "< 0:252-55.el9_7.9 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:252-55.el9_7.9"
          }
        }
      ],
      "artifact": {
        "id": "127de483e2efb7b9",
        "name": "systemd-rpm-macros",
        "version": "252-55.el9_7.8",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+ and MIT and GPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:systemd-rpm-macros:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd-rpm-macros:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_rpm_macros:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_rpm_macros:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd-rpm:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd-rpm:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_rpm:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd_rpm:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:systemd:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd-rpm-macros:252-55.el9_7.8:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:systemd_rpm_macros:252-55.el9_7.8:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/systemd-rpm-macros@252-55.el9_7.8?arch=noarch&distro=rhel-9.7&upstream=systemd-252-55.el9_7.8.src.rpm",
        "upstreams": [
          {
            "name": "systemd",
            "version": "252-55.el9_7.8"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "noarch"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-13757",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-13757",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.2,
              "exploitabilityScore": 2.6,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-13757",
            "epss": 0.00136,
            "percentile": 0.03456,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-13757",
            "cwe": "CWE-674",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.07616
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-13757",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-13757",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:37469",
            "https://access.redhat.com/errata/RHSA-2026:38342",
            "https://access.redhat.com/security/cve/CVE-2026-13757",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2494556",
            "https://github.com/advisories/GHSA-p2wm-69qx-x25w"
          ],
          "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.2,
                "exploitabilityScore": 2.6,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-13757",
              "epss": 0.00136,
              "percentile": 0.03456,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-13757",
              "cwe": "CWE-674",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "p11-kit",
              "version": "0:0.25.3-3.el9_5"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-13757",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "39edf0f240a77402",
        "name": "p11-kit",
        "version": "0.25.3-3.el9_5",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD-3-Clause"
        ],
        "cpes": [
          "cpe:2.3:a:p11-kit:p11-kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11-kit:p11_kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit:p11-kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit:p11_kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:p11-kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:p11_kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11:p11-kit:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11:p11_kit:0.25.3-3.el9_5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/p11-kit@0.25.3-3.el9_5?arch=x86_64&distro=rhel-9.7&upstream=p11-kit-0.25.3-3.el9_5.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-13757",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-13757",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.2,
              "exploitabilityScore": 2.6,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-13757",
            "epss": 0.00136,
            "percentile": 0.03456,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-13757",
            "cwe": "CWE-674",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.07616
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-13757",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-13757",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:37469",
            "https://access.redhat.com/errata/RHSA-2026:38342",
            "https://access.redhat.com/security/cve/CVE-2026-13757",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2494556",
            "https://github.com/advisories/GHSA-p2wm-69qx-x25w"
          ],
          "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.2,
                "exploitabilityScore": 2.6,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-13757",
              "epss": 0.00136,
              "percentile": 0.03456,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-13757",
              "cwe": "CWE-674",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "p11-kit",
              "version": "0.25.3-3.el9_5"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-13757",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "546bedf3e2fa6b85",
        "name": "p11-kit-trust",
        "version": "0.25.3-3.el9_5",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD-3-Clause"
        ],
        "cpes": [
          "cpe:2.3:a:p11-kit-trust:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11-kit-trust:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit_trust:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit_trust:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11-kit:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11-kit:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11_kit:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11:p11-kit-trust:0.25.3-3.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:p11:p11_kit_trust:0.25.3-3.el9_5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/p11-kit-trust@0.25.3-3.el9_5?arch=x86_64&distro=rhel-9.7&upstream=p11-kit-0.25.3-3.el9_5.src.rpm",
        "upstreams": [
          {
            "name": "p11-kit",
            "version": "0.25.3-3.el9_5"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-22185",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-22185",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load. When processing malformed input, a local attacker can exploit a heap buffer underflow vulnerability in the readline() function. This can lead to an out-of-bounds read, potentially causing a denial of service (DoS) and limited disclosure of heap memory contents.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 2.6,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-22185",
            "epss": 0.00127,
            "percentile": 0.02724,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-22185",
            "cwe": "CWE-125",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-22185",
            "cwe": "CWE-191",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.07493000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-22185",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-22185",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://bugs.openldap.org/show_bug.cgi?id=10421",
            "https://seclists.org/fulldisclosure/2026/Jan/5",
            "https://seclists.org/fulldisclosure/2026/Jan/8",
            "https://www.openldap.org/",
            "https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"
          ],
          "description": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.",
          "cvss": [
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 4.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-22185",
              "epss": 0.00127,
              "percentile": 0.02724,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-22185",
              "cwe": "CWE-125",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-22185",
              "cwe": "CWE-191",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "openldap",
              "version": "0:2.6.8-4.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-22185",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "88f70f8a830c0797",
        "name": "openldap",
        "version": "2.6.8-4.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "OLDAP-2.8"
        ],
        "cpes": [
          "cpe:2.3:a:openldap:openldap:2.6.8-4.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:openldap:2.6.8-4.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=rhel-9.7&upstream=openldap-2.6.8-4.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-56391",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-56391",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GNU coreutils uniq. When processing specially crafted multibyte input with the --check-chars option, an attacker can trigger an out-of-bounds read. This vulnerability can lead to a denial of service (DoS) due to an application crash and potentially expose sensitive information from adjacent memory.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.1,
              "exploitabilityScore": 1.9,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-56391",
            "epss": 0.00135,
            "percentile": 0.0334,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-56391",
            "cwe": "CWE-125",
            "source": "cvd@cert.pl",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.07492499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-56391",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-56391",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://cert.pl/en/posts/2026/07/CVE-2026-56391",
            "https://git.savannah.gnu.org/cgit/coreutils.git/",
            "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"
          ],
          "description": "GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
          "cvss": [
            {
              "source": "cvd@cert.pl",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 4.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-56391",
              "epss": 0.00135,
              "percentile": 0.0334,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-56391",
              "cwe": "CWE-125",
              "source": "cvd@cert.pl",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "coreutils",
              "version": "8.32-39.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-56391",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8ef168befafd7b27",
        "name": "coreutils-single",
        "version": "8.32-39.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+"
        ],
        "cpes": [
          "cpe:2.3:a:coreutils-single:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils-single:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils_single:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils_single:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/coreutils-single@8.32-39.el9?arch=x86_64&distro=rhel-9.7&upstream=coreutils-8.32-39.el9.src.rpm",
        "upstreams": [
          {
            "name": "coreutils",
            "version": "8.32-39.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-54371",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-54371",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the `attr` package. This vulnerability allows a local attacker to perform a symlink traversal attack by replacing a pathname component with a symbolic link - either during directory hierarchy traversal by `getfattr` or during backup restoration by `setfattr`, which reads and resolves full pathnames from backup files. In both cases, when these utilities are executed by a privileged process over a path controlled by the attacker, this can lead to local privilege escalation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 6.3,
              "exploitabilityScore": 1.1,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-54371",
            "epss": 0.00131,
            "percentile": 0.03071,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-54371",
            "cwe": "CWE-59",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-54371",
            "cwe": "CWE-59",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.07401499999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-54371",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-54371",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f",
            "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b",
            "https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr",
            "https://access.redhat.com/errata/RHSA-2026:34889",
            "https://access.redhat.com/security/cve/CVE-2026-54371",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2490283",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"
          ],
          "description": "attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 6.3,
                "exploitabilityScore": 1.1,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 8.4
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 1.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-54371",
              "epss": 0.00131,
              "percentile": 0.03071,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-54371",
              "cwe": "CWE-59",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-54371",
              "cwe": "CWE-59",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "attr",
              "version": "2.5.1-3.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-54371",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "304e2047f10e5c4f",
        "name": "libattr",
        "version": "2.5.1-3.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libattr:libattr:2.5.1-3.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libattr:2.5.1-3.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=rhel-9.7&upstream=attr-2.5.1-3.el9.src.rpm",
        "upstreams": [
          {
            "name": "attr",
            "version": "2.5.1-3.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11979",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-11979",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libxml2, specifically within the xmlcatalog utility when operating in shell mode. An attacker can exploit multiple stack-based buffer overflows by providing an excessively long input line. This leads to memory corruption, which may cause the application to crash or potentially allow the attacker to execute arbitrary code within the context of the xmlcatalog process.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
            "metrics": {
              "baseScore": 4.8,
              "exploitabilityScore": 1.4,
              "impactScore": 3.4
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-11979",
            "epss": 0.00148,
            "percentile": 0.04492,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11979",
            "cwe": "CWE-121",
            "source": "cvd@cert.pl",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.07252
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11979",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11979",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cert.pl/en/posts/2026/06/CVE-2026-11979",
            "https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e"
          ],
          "description": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.\nBy supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.\nSuccessful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.\n\nThis issue has been fixed in the commit c2e233fc.\n\nNOTE:\nThe maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 7.8,
                "exploitabilityScore": 1.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "cvd@cert.pl",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 1.8
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11979",
              "epss": 0.00148,
              "percentile": 0.04492,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11979",
              "cwe": "CWE-121",
              "source": "cvd@cert.pl",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libxml2",
              "version": "0:2.9.13-14.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11979",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a840257087cebda4",
        "name": "libxml2",
        "version": "2.9.13-14.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libxml2-2.9.13-14.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-15028",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-15028",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L",
            "metrics": {
              "baseScore": 3.9,
              "exploitabilityScore": 1.4,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-15028",
            "epss": 0.00203,
            "percentile": 0.10527,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-15028",
            "cwe": "CWE-122",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.070035
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-15028",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-15028",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:38279",
            "https://access.redhat.com/security/cve/CVE-2026-15028",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2497970",
            "https://github.com/libarchive/libarchive/issues/3251",
            "https://github.com/libarchive/libarchive/pull/3253"
          ],
          "description": "A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 3.9,
                "exploitabilityScore": 1.4,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-15028",
              "epss": 0.00203,
              "percentile": 0.10527,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-15028",
              "cwe": "CWE-122",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-15028",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-56392",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-56392",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This vulnerability, a heap-based buffer overflow, occurs due to an integer overflow when `unexpand` processes unusually large tab stop values provided by a local attacker. This can lead to an undersized memory buffer, allowing subsequent operations to write beyond its boundaries. Successful exploitation can cause the `unexpand` utility to crash, potentially resulting in a denial of service or enabling further memory manipulation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 4.4,
              "exploitabilityScore": 1.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-56392",
            "epss": 0.00149,
            "percentile": 0.04535,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-56392",
            "cwe": "CWE-122",
            "source": "cvd@cert.pl",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.07003000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-56392",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-56392",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://cert.pl/en/posts/2026/07/CVE-2026-56391",
            "https://git.savannah.gnu.org/cgit/coreutils.git/",
            "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"
          ],
          "description": "GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d",
          "cvss": [
            {
              "source": "cvd@cert.pl",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 1.8
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-56392",
              "epss": 0.00149,
              "percentile": 0.04535,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-56392",
              "cwe": "CWE-122",
              "source": "cvd@cert.pl",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "coreutils",
              "version": "8.32-39.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-56392",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8ef168befafd7b27",
        "name": "coreutils-single",
        "version": "8.32-39.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+"
        ],
        "cpes": [
          "cpe:2.3:a:coreutils-single:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils-single:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils_single:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils_single:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:coreutils:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:coreutils-single:8.32-39.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:coreutils_single:8.32-39.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/coreutils-single@8.32-39.el9?arch=x86_64&distro=rhel-9.7&upstream=coreutils-8.32-39.el9.src.rpm",
        "upstreams": [
          {
            "name": "coreutils",
            "version": "8.32-39.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-51298",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-51298",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in SQLite. A remote attacker could exploit a use-after-free vulnerability in the JSON extraction function. This occurs when the program attempts to access memory after it has been freed, specifically within the `JsonParse` object. Successful exploitation of this vulnerability can lead to a service crash and a denial of service (DoS) for affected systems.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-51298",
            "epss": 0.00112,
            "percentile": 0.01611,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-51298",
            "cwe": "CWE-416",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.06999999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-51298",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-51298",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51298",
            "https://github.com/sqlite/sqlite/blob/master/src/json.c"
          ],
          "description": "sqlite 3.41 is vulnerable to use after free in the JSON extraction function. After releasing JsonParse object memory via jsonParseFree(), the program still accesses internal member of the freed pointer, which can cause service crash and denial of service.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.2,
                "exploitabilityScore": 2.6,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-51298",
              "epss": 0.00112,
              "percentile": 0.01611,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-51298",
              "cwe": "CWE-416",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "sqlite",
              "version": "3.34.1-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-51298",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "1bd197aae1b6fd3b",
        "name": "sqlite-libs",
        "version": "3.34.1-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite-libs:3.34.1-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:sqlite:sqlite_libs:3.34.1-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/sqlite-libs@3.34.1-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=sqlite-3.34.1-9.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "sqlite",
            "version": "3.34.1-9.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-12610",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-12610",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 6.4,
              "exploitabilityScore": 0.5,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-12610",
            "epss": 0.00121,
            "percentile": 0.0229,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-12610",
            "cwe": "CWE-825",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.06897
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-12610",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-12610",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-12610",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2490288",
            "https://github.com/SSSD/sssd/issues/8796"
          ],
          "description": "A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 6.4,
                "exploitabilityScore": 0.5,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-12610",
              "epss": 0.00121,
              "percentile": 0.0229,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-12610",
              "cwe": "CWE-825",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "pam",
              "version": "0:1.5.1-26.el9_6"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-12610",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "9dd847ac0d635e43",
        "name": "pam",
        "version": "1.5.1-26.el9_6",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD and GPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:pam:1.5.1-26.el9_6:*:*:*:*:*:*:*",
          "cpe:2.3:a:pam:pam:1.5.1-26.el9_6:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/pam@1.5.1-26.el9_6?arch=x86_64&distro=rhel-9.7&upstream=pam-1.5.1-26.el9_6.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-27171",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-27171",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in zlib. An attacker providing specially crafted input to the `crc32_combine64` or `crc32_combine_gen64` functions could trigger an infinite loop within the `x2nmodp` function. This leads to excessive CPU consumption, which can result in a Denial of Service (DoS) for the affected system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.3,
              "exploitabilityScore": 1.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-27171",
            "epss": 0.00218,
            "percentile": 0.1244,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-27171",
            "cwe": "CWE-1284",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.06867
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-27171",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-27171",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/",
            "https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf",
            "https://github.com/madler/zlib/issues/904",
            "https://github.com/madler/zlib/releases/tag/v1.3.2",
            "https://ostif.org/zlib-audit-complete/"
          ],
          "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-27171",
              "epss": 0.00218,
              "percentile": 0.1244,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-27171",
              "cwe": "CWE-1284",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "zlib",
              "version": "0:1.2.11-40.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-27171",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "3b95a370d9cbeb72",
        "name": "zlib",
        "version": "1.2.11-40.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "zlib and Boost"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:zlib:1.2.11-40.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:zlib:zlib:1.2.11-40.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=rhel-9.7&upstream=zlib-1.2.11-40.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-56412",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-56412",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libexpat. This vulnerability, present in versions before 2.8.2, stems from improper handling of XML CDATA sections, where the library fails to adequately track the depth of handler calls. This can result in a 'use-after-free' error, a type of memory corruption that could allow an attacker to crash the application or potentially gain unauthorized control.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "metrics": {
              "baseScore": 4.9,
              "exploitabilityScore": 1.5,
              "impactScore": 3.4
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-56412",
            "epss": 0.00138,
            "percentile": 0.03587,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-56412",
            "cwe": "CWE-416",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.06831
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-56412",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-56412",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/libexpat/libexpat/pull/1278"
          ],
          "description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.6,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 4.9,
                "exploitabilityScore": 1.5,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-56412",
              "epss": 0.00138,
              "percentile": 0.03587,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-56412",
              "cwe": "CWE-416",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-56412",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-13595",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-13595",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 2.6,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-13595",
            "epss": 0.0011,
            "percentile": 0.01474,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-13595",
            "cwe": "CWE-416",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0649
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-13595",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:26573",
            "https://access.redhat.com/security/cve/CVE-2026-13595",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2494101",
            "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
          ],
          "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.1,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 6.8,
                "exploitabilityScore": 2.6,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-13595",
              "epss": 0.0011,
              "percentile": 0.01474,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-13595",
              "cwe": "CWE-416",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-13595",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "13c59f3cea6969c1",
        "name": "libblkid",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libblkid:libblkid:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libblkid:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libblkid@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-13595",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-13595",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 2.6,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-13595",
            "epss": 0.0011,
            "percentile": 0.01474,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-13595",
            "cwe": "CWE-416",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0649
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-13595",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:26573",
            "https://access.redhat.com/security/cve/CVE-2026-13595",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2494101",
            "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
          ],
          "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.1,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 6.8,
                "exploitabilityScore": 2.6,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-13595",
              "epss": 0.0011,
              "percentile": 0.01474,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-13595",
              "cwe": "CWE-416",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-13595",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "9b20fa5a00b5d889",
        "name": "libfdisk",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libfdisk:libfdisk:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libfdisk:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libfdisk@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-13595",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-13595",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 2.6,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-13595",
            "epss": 0.0011,
            "percentile": 0.01474,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-13595",
            "cwe": "CWE-416",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0649
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-13595",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:26573",
            "https://access.redhat.com/security/cve/CVE-2026-13595",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2494101",
            "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
          ],
          "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.1,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 6.8,
                "exploitabilityScore": 2.6,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-13595",
              "epss": 0.0011,
              "percentile": 0.01474,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-13595",
              "cwe": "CWE-416",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-13595",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "523e383e4618dcda",
        "name": "libmount",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libmount:libmount:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libmount:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libmount@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-13595",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-13595",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 2.6,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-13595",
            "epss": 0.0011,
            "percentile": 0.01474,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-13595",
            "cwe": "CWE-416",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0649
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-13595",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:26573",
            "https://access.redhat.com/security/cve/CVE-2026-13595",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2494101",
            "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
          ],
          "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.1,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 6.8,
                "exploitabilityScore": 2.6,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-13595",
              "epss": 0.0011,
              "percentile": 0.01474,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-13595",
              "cwe": "CWE-416",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-13595",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "32b3d88bd8711736",
        "name": "libsmartcols",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libsmartcols:libsmartcols:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libsmartcols:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libsmartcols@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-13595",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-13595",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 2.6,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-13595",
            "epss": 0.0011,
            "percentile": 0.01474,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-13595",
            "cwe": "CWE-416",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0649
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-13595",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:26573",
            "https://access.redhat.com/security/cve/CVE-2026-13595",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2494101",
            "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
          ],
          "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.1,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 6.8,
                "exploitabilityScore": 2.6,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-13595",
              "epss": 0.0011,
              "percentile": 0.01474,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-13595",
              "cwe": "CWE-416",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-13595",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "5d74f51dbb602efa",
        "name": "libuuid",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libuuid:libuuid:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libuuid:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libuuid@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-13595",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-13595",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 2.6,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-13595",
            "epss": 0.0011,
            "percentile": 0.01474,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-13595",
            "cwe": "CWE-416",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0649
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-13595",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:26573",
            "https://access.redhat.com/security/cve/CVE-2026-13595",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2494101",
            "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
          ],
          "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.1,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 6.8,
                "exploitabilityScore": 2.6,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-13595",
              "epss": 0.0011,
              "percentile": 0.01474,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-13595",
              "cwe": "CWE-416",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "0:2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-13595",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "90ace28f4fd2396b",
        "name": "util-linux",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv2 and GPLv2+ and LGPLv2+ and BSD with advertising and Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:util-linux:util-linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util-linux:util_linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux:util-linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux:util_linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:util-linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:util_linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util:util-linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util:util_linux:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/util-linux@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-13595",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-13595",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.8,
              "exploitabilityScore": 2.6,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-13595",
            "epss": 0.0011,
            "percentile": 0.01474,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-13595",
            "cwe": "CWE-416",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0649
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-13595",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:26573",
            "https://access.redhat.com/security/cve/CVE-2026-13595",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2494101",
            "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
          ],
          "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.1,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 6.8,
                "exploitabilityScore": 2.6,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-13595",
              "epss": 0.0011,
              "percentile": 0.01474,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-13595",
              "cwe": "CWE-416",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-13595",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "523dbbd84ad44779",
        "name": "util-linux-core",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv2 and GPLv2+ and LGPLv2+ and BSD with advertising and Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:util-linux-core:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util-linux-core:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux_core:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux_core:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util-linux:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util-linux:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/util-linux-core@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-41991",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-41991",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the `gzexe` utility of GNU `gzip`. When the `mktemp` utility is not available, `gzexe` creates temporary files with predictable names based on the process ID. A local attacker can exploit this by pre-creating a symbolic link to an arbitrary file at the predicted temporary file path. This can lead to a Time-of-Check to Time-of-Use (TOCTOU) condition, allowing the attacker to overwrite arbitrary files on the system.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H",
            "metrics": {
              "baseScore": 6,
              "exploitabilityScore": 0.8,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-41991",
            "epss": 0.00117,
            "percentile": 0.01954,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-41991",
            "cwe": "CWE-377",
            "source": "cvd@cert.pl",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.06435
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-41991",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-41991",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://cert.pl/en/posts/2026/04/CVE-2026-41991/",
            "https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269",
            "https://www.gnu.org/software/gzip/"
          ],
          "description": "GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.\n\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cvd@cert.pl",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-41991",
              "epss": 0.00117,
              "percentile": 0.01954,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-41991",
              "cwe": "CWE-377",
              "source": "cvd@cert.pl",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gzip",
              "version": "0:1.12-1.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-41991",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7380a2a1c814e175",
        "name": "gzip",
        "version": "1.12-1.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+ and GFDL"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:gzip:1.12-1.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:gzip:gzip:1.12-1.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=rhel-9.7&upstream=gzip-1.12-1.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-56132",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-56132",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libexpat, a library used for parsing XML data. An attacker could exploit a heap-based buffer overflow, a type of memory error, by providing specially crafted XML input. This vulnerability occurs when the library mishandles memory reallocation while processing XML, particularly when multiple parsers share data. Successful exploitation could allow the attacker to execute arbitrary code, access sensitive information, or cause the application to crash, leading to a denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "metrics": {
              "baseScore": 6.9,
              "exploitabilityScore": 1.5,
              "impactScore": 5.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-56132",
            "epss": 0.00107,
            "percentile": 0.01331,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-56132",
            "cwe": "CWE-821",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.063665
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-56132",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-56132",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/libexpat/libexpat/pull/1272"
          ],
          "description": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
              "metrics": {
                "baseScore": 6.9,
                "exploitabilityScore": 1.5,
                "impactScore": 5.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
              "metrics": {
                "baseScore": 6.9,
                "exploitabilityScore": 1.5,
                "impactScore": 5.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-56132",
              "epss": 0.00107,
              "percentile": 0.01331,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-56132",
              "cwe": "CWE-821",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-56132",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42250",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-42250",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in bzip2. The bzip2recover utility contains an off-by-one error that allows a local attacker to cause an out-of-bounds write to a global buffer by processing a specially crafted file. This memory corruption can lead to a crash, resulting in a Denial of Service (DoS).",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5,
              "exploitabilityScore": 1.4,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42250",
            "epss": 0.00126,
            "percentile": 0.02697,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42250",
            "cwe": "CWE-787",
            "source": "cvd@cert.pl",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.063
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42250",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42250",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://cert.pl/en/posts/2026/05/CVE-2026-42250/",
            "https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/",
            "https://sourceware.org/bzip2/",
            "https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"
          ],
          "description": "bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67",
          "cvss": [
            {
              "source": "cvd@cert.pl",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 4.8
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42250",
              "epss": 0.00126,
              "percentile": 0.02697,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42250",
              "cwe": "CWE-787",
              "source": "cvd@cert.pl",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "bzip2",
              "version": "1.0.8-10.el9_5"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42250",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17802e5820eaaec1",
        "name": "bzip2-libs",
        "version": "1.0.8-10.el9_5",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:bzip2-libs:bzip2-libs:1.0.8-10.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:bzip2-libs:bzip2_libs:1.0.8-10.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:bzip2_libs:bzip2-libs:1.0.8-10.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:bzip2_libs:bzip2_libs:1.0.8-10.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:bzip2-libs:1.0.8-10.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:bzip2_libs:1.0.8-10.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:bzip2:bzip2-libs:1.0.8-10.el9_5:*:*:*:*:*:*:*",
          "cpe:2.3:a:bzip2:bzip2_libs:1.0.8-10.el9_5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/bzip2-libs@1.0.8-10.el9_5?arch=x86_64&distro=rhel-9.7&upstream=bzip2-1.0.8-10.el9_5.src.rpm",
        "upstreams": [
          {
            "name": "bzip2",
            "version": "1.0.8-10.el9_5"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-56405",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-56405",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in libexpat. An integer overflow vulnerability exists within the `getAttributeId` function. This flaw could allow an attacker to potentially disclose sensitive information or execute arbitrary code, leading to a compromise of the system's integrity and confidentiality.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "metrics": {
              "baseScore": 4.9,
              "exploitabilityScore": 1.5,
              "impactScore": 3.4
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-56405",
            "epss": 0.00125,
            "percentile": 0.02566,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-56405",
            "cwe": "CWE-190",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.061875000000000006
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-56405",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-56405",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/libexpat/libexpat/pull/1251"
          ],
          "description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
              "metrics": {
                "baseScore": 6.9,
                "exploitabilityScore": 1.5,
                "impactScore": 5.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
              "metrics": {
                "baseScore": 6.9,
                "exploitabilityScore": 1.5,
                "impactScore": 5.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-56405",
              "epss": 0.00125,
              "percentile": 0.02566,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-56405",
              "cwe": "CWE-190",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-56405",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-66382",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-66382",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in libexpat. This vulnerability allows a denial of service (DoS) by processing a crafted file with an approximate size of 2 MiB, leading to dozens of seconds of processing time.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 2.9,
              "exploitabilityScore": 1.5,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-66382",
            "epss": 0.00206,
            "percentile": 0.1085,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-66382",
            "cwe": "CWE-407",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.060770000000000005
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-66382",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-66382",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/libexpat/libexpat/issues/1076",
            "http://www.openwall.com/lists/oss-security/2025/12/02/1",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
          ],
          "description": "In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-66382",
              "epss": 0.00206,
              "percentile": 0.1085,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-66382",
              "cwe": "CWE-407",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-66382",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-27456",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-27456",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-27456",
            "epss": 0.00118,
            "percentile": 0.01987,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-59",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-269",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.057229999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-27456",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4",
            "https://github.com/util-linux/util-linux/releases/tag/v2.41.4",
            "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
          ],
          "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
          "cvss": [
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-27456",
              "epss": 0.00118,
              "percentile": 0.01987,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-59",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-269",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-27456",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "13c59f3cea6969c1",
        "name": "libblkid",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libblkid:libblkid:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libblkid:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libblkid@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-27456",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-27456",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-27456",
            "epss": 0.00118,
            "percentile": 0.01987,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-59",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-269",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.057229999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-27456",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4",
            "https://github.com/util-linux/util-linux/releases/tag/v2.41.4",
            "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
          ],
          "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
          "cvss": [
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-27456",
              "epss": 0.00118,
              "percentile": 0.01987,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-59",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-269",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-27456",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "9b20fa5a00b5d889",
        "name": "libfdisk",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libfdisk:libfdisk:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libfdisk:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libfdisk@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-27456",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-27456",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-27456",
            "epss": 0.00118,
            "percentile": 0.01987,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-59",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-269",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.057229999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-27456",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4",
            "https://github.com/util-linux/util-linux/releases/tag/v2.41.4",
            "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
          ],
          "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
          "cvss": [
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-27456",
              "epss": 0.00118,
              "percentile": 0.01987,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-59",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-269",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-27456",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "523e383e4618dcda",
        "name": "libmount",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libmount:libmount:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libmount:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libmount@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-27456",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-27456",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-27456",
            "epss": 0.00118,
            "percentile": 0.01987,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-59",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-269",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.057229999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-27456",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4",
            "https://github.com/util-linux/util-linux/releases/tag/v2.41.4",
            "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
          ],
          "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
          "cvss": [
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-27456",
              "epss": 0.00118,
              "percentile": 0.01987,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-59",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-269",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-27456",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "32b3d88bd8711736",
        "name": "libsmartcols",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libsmartcols:libsmartcols:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libsmartcols:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libsmartcols@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-27456",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-27456",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-27456",
            "epss": 0.00118,
            "percentile": 0.01987,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-59",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-269",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.057229999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-27456",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4",
            "https://github.com/util-linux/util-linux/releases/tag/v2.41.4",
            "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
          ],
          "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
          "cvss": [
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-27456",
              "epss": 0.00118,
              "percentile": 0.01987,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-59",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-269",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-27456",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "5d74f51dbb602efa",
        "name": "libuuid",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libuuid:libuuid:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libuuid:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libuuid@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-27456",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-27456",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-27456",
            "epss": 0.00118,
            "percentile": 0.01987,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-59",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-269",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.057229999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-27456",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4",
            "https://github.com/util-linux/util-linux/releases/tag/v2.41.4",
            "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
          ],
          "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
          "cvss": [
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-27456",
              "epss": 0.00118,
              "percentile": 0.01987,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-59",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-269",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "0:2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-27456",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "90ace28f4fd2396b",
        "name": "util-linux",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv2 and GPLv2+ and LGPLv2+ and BSD with advertising and Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:util-linux:util-linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util-linux:util_linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux:util-linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux:util_linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:util-linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:util_linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util:util-linux:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util:util_linux:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/util-linux@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-27456",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-27456",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-27456",
            "epss": 0.00118,
            "percentile": 0.01987,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-59",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-269",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27456",
            "cwe": "CWE-367",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.057229999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-27456",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4",
            "https://github.com/util-linux/util-linux/releases/tag/v2.41.4",
            "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
          ],
          "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
          "cvss": [
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-27456",
              "epss": 0.00118,
              "percentile": 0.01987,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-59",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-269",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27456",
              "cwe": "CWE-367",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "util-linux",
              "version": "2.37.4-21.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-27456",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "523dbbd84ad44779",
        "name": "util-linux-core",
        "version": "2.37.4-21.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv2 and GPLv2+ and LGPLv2+ and BSD with advertising and Public Domain"
        ],
        "cpes": [
          "cpe:2.3:a:util-linux-core:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util-linux-core:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux_core:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux_core:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util-linux:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util-linux:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util_linux:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util:util-linux-core:2.37.4-21.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:util:util_linux_core:2.37.4-21.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/util-linux-core@2.37.4-21.el9_7?arch=x86_64&distro=rhel-9.7&upstream=util-linux-2.37.4-21.el9_7.src.rpm",
        "upstreams": [
          {
            "name": "util-linux",
            "version": "2.37.4-21.el9_7"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-68972",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-68972",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GnuPG. An adversary can exploit this vulnerability by crafting a signed message that includes a form feed character (\\f) at the end of a plaintext line. This allows the adversary to append additional, unsigned text to the message while the signature verification still reports success. This issue leads to an integrity bypass, potentially enabling the spoofing of signed communications.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 1.5,
              "impactScore": 4
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-68972",
            "epss": 0.00105,
            "percentile": 0.01266,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-68972",
            "cwe": "CWE-347",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.057225000000000005
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-68972",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-68972",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://gpg.fail/formfeed",
            "https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i",
            "https://news.ycombinator.com/item?id=46404339"
          ],
          "description": "In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 1.5,
                "impactScore": 4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-68972",
              "epss": 0.00105,
              "percentile": 0.01266,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-68972",
              "cwe": "CWE-347",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnupg2",
              "version": "0:2.3.3-5.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-68972",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "6612ed205a98e91d",
        "name": "gnupg2",
        "version": "2.3.3-5.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+"
        ],
        "cpes": [
          "cpe:2.3:a:gnupg2:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnupg2-2.3.3-5.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-6170",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-6170",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 2.5,
              "exploitabilityScore": 1.1,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-6170",
            "epss": 0.00207,
            "percentile": 0.11,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-6170",
            "cwe": "CWE-121",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.9.13-14.el9_8.2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.9.13-14.el9_8.2",
              "date": "2026-07-15",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:39317",
            "link": "https://access.redhat.com/errata/RHSA-2026:39317"
          }
        ],
        "risk": 0.056924999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-6170",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-6170",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:36734",
            "https://access.redhat.com/errata/RHSA-2026:39304",
            "https://access.redhat.com/errata/RHSA-2026:39317",
            "https://access.redhat.com/errata/RHSA-2026:44481",
            "https://access.redhat.com/errata/RHSA-2026:46836",
            "https://access.redhat.com/errata/RHSA-2026:7519",
            "https://access.redhat.com/security/cve/CVE-2025-6170",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2372952",
            "https://gitlab.gnome.org/GNOME/libxml2/-/issues/941",
            "https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
          ],
          "description": "A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.5,
                "exploitabilityScore": 1.1,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.5,
                "exploitabilityScore": 1.1,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-6170",
              "epss": 0.00207,
              "percentile": 0.11,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-6170",
              "cwe": "CWE-121",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libxml2",
              "version": "0:2.9.13-14.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-6170",
            "versionConstraint": "< 0:2.9.13-14.el9_8.2 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.9.13-14.el9_8.2"
          }
        }
      ],
      "artifact": {
        "id": "a840257087cebda4",
        "name": "libxml2",
        "version": "2.9.13-14.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libxml2-2.9.13-14.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-16730",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-16730",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 1.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-16730",
            "epss": 0.00107,
            "percentile": 0.01336,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-16730",
            "cwe": "CWE-755",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.056174999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-16730",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-16730",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-16730",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2506348",
            "https://github.com/bus1/dbus-broker/issues/435"
          ],
          "description": "A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-16730",
              "epss": 0.00107,
              "percentile": 0.01336,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-16730",
              "cwe": "CWE-755",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "dbus-broker",
              "version": "0:28-7.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-16730",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30a9caec9b9811a7",
        "name": "dbus-broker",
        "version": "28-7.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "ASL 2.0"
        ],
        "cpes": [
          "cpe:2.3:a:dbus-broker:dbus-broker:28-7.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:dbus-broker:dbus_broker:28-7.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:dbus_broker:dbus-broker:28-7.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:dbus_broker:dbus_broker:28-7.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:dbus-broker:28-7.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:dbus_broker:28-7.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:dbus:dbus-broker:28-7.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:dbus:dbus_broker:28-7.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=rhel-9.7&upstream=dbus-broker-28-7.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-41990",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-41990",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in Libgcrypt. During Dilithium signing operations, the library fails to perform a bounds check when writing to a static array. While the data involved is not directly controlled by an attacker, this vulnerability could lead to memory corruption, potentially resulting in a denial of service (DoS) or affecting data integrity.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 3.3,
              "exploitabilityScore": 0.8,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-41990",
            "epss": 0.00176,
            "percentile": 0.07372,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-41990",
            "cwe": "CWE-787",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.05543999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-41990",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-41990",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://dev.gnupg.org/T8208",
            "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html",
            "https://www.openwall.com/lists/oss-security/2026/04/21/1"
          ],
          "description": "Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.",
          "cvss": [
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
              "metrics": {
                "baseScore": 4,
                "exploitabilityScore": 1.5,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-41990",
              "epss": 0.00176,
              "percentile": 0.07372,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-41990",
              "cwe": "CWE-787",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libgcrypt",
              "version": "0:1.10.0-11.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-41990",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "bdcb3bee3b1ed812",
        "name": "libgcrypt",
        "version": "1.10.0-11.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libgcrypt:libgcrypt:1.10.0-11.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libgcrypt:1.10.0-11.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=rhel-9.7&upstream=libgcrypt-1.10.0-11.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-5916",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-5916",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L",
            "metrics": {
              "baseScore": 3.9,
              "exploitabilityScore": 1.4,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-5916",
            "epss": 0.00155,
            "percentile": 0.05119,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-5916",
            "cwe": "CWE-190",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.053474999999999995
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-5916",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-5916",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2025-5916",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2370872",
            "https://github.com/libarchive/libarchive/pull/2568",
            "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
          ],
          "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5.6,
                "exploitabilityScore": 1.4,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 3.9,
                "exploitabilityScore": 1.4,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-5916",
              "epss": 0.00155,
              "percentile": 0.05119,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-5916",
              "cwe": "CWE-190",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-5916",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-30258",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-30258",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in GnuPG. In affected versions, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, leading to a verification denial of service.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 2.7,
              "exploitabilityScore": 1.1,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-30258",
            "epss": 0.00183,
            "percentile": 0.08184,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-30258",
            "cwe": "CWE-754",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.05215500000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-30258",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-30258",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://dev.gnupg.org/T7527",
            "https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158",
            "https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"
          ],
          "description": "In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.7,
                "exploitabilityScore": 1.1,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-30258",
              "epss": 0.00183,
              "percentile": 0.08184,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-30258",
              "cwe": "CWE-754",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnupg2",
              "version": "0:2.3.3-5.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-30258",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "6612ed205a98e91d",
        "name": "gnupg2",
        "version": "2.3.3-5.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+"
        ],
        "cpes": [
          "cpe:2.3:a:gnupg2:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnupg2-2.3.3-5.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-14017",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-14017",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When performing multi-threaded LDAPS (Lightweight Directory Access Protocol Secure) transfers, changes to Transport Layer Security (TLS) options in one thread could inadvertently apply globally, affecting other concurrent transfers. This could lead to unintended security posture changes, such as disabling certificate verification for other threads. This vulnerability can result in a security bypass, where expected security checks are not performed.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 4.8,
              "exploitabilityScore": 2.3,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-14017",
            "epss": 0.00106,
            "percentile": 0.01282,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-14017",
            "cwe": "NVD-CWE-Other",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.05193999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-14017",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-14017.html",
            "https://curl.se/docs/CVE-2025-14017.json",
            "http://www.openwall.com/lists/oss-security/2026/01/07/3"
          ],
          "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 6.3,
                "exploitabilityScore": 1.1,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-14017",
              "epss": 0.00106,
              "percentile": 0.01282,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-14017",
              "cwe": "NVD-CWE-Other",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-14017",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "80060905a7bc7a57",
        "name": "curl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:curl:curl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/curl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-14017",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-14017",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in curl. When performing multi-threaded LDAPS (Lightweight Directory Access Protocol Secure) transfers, changes to Transport Layer Security (TLS) options in one thread could inadvertently apply globally, affecting other concurrent transfers. This could lead to unintended security posture changes, such as disabling certificate verification for other threads. This vulnerability can result in a security bypass, where expected security checks are not performed.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 4.8,
              "exploitabilityScore": 2.3,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-14017",
            "epss": 0.00106,
            "percentile": 0.01282,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-14017",
            "cwe": "NVD-CWE-Other",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.05193999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-14017",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-14017.html",
            "https://curl.se/docs/CVE-2025-14017.json",
            "http://www.openwall.com/lists/oss-security/2026/01/07/3"
          ],
          "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 6.3,
                "exploitabilityScore": 1.1,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-14017",
              "epss": 0.00106,
              "percentile": 0.01282,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-14017",
              "cwe": "NVD-CWE-Other",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "curl",
              "version": "7.76.1-35.el9_7.3"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-14017",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "17f6388a8875d95e",
        "name": "libcurl-minimal",
        "version": "7.76.1-35.el9_7.3",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl-minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libcurl_minimal:7.76.1-35.el9_7.3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libcurl-minimal@7.76.1-35.el9_7.3?arch=x86_64&distro=rhel-9.7&upstream=curl-7.76.1-35.el9_7.3.src.rpm",
        "upstreams": [
          {
            "name": "curl",
            "version": "7.76.1-35.el9_7.3"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-24515",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-24515",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A null pointer dereference flaw has been discovered in libexpat. The function `XML_ExternalEntityParserCreate` failed to copy the encoding handler data passed to XML_SetUnknownEncodingHandler from the parent to the new subparser. This can cause a NULL dereference from external entities that declare use of an unknown encoding. The expected impact is denial of service. It takes use of both functions `XML_ExternalEntityParserCreate` and `XML_SetUnknownEncodingHandler` for an application to be vulnerable.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 2.9,
              "exploitabilityScore": 1.5,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-24515",
            "epss": 0.0017,
            "percentile": 0.06697,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-24515",
            "cwe": "CWE-476",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.05015
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-24515",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-24515",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://github.com/libexpat/libexpat/pull/1131",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
          ],
          "description": "In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.5,
                "exploitabilityScore": 1.1,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-24515",
              "epss": 0.0017,
              "percentile": 0.06697,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-24515",
              "cwe": "CWE-476",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "expat",
              "version": "0:2.5.0-5.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-24515",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8d62d2fd9a412188",
        "name": "expat",
        "version": "2.5.0-5.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "MIT"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:expat:expat:2.5.0-5.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/expat@2.5.0-5.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=expat-2.5.0-5.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-54370",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-54370",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A time-of-check to time-of-use (TOCTOU) race condition vulnerability was found in `acl`. By replacing a pathname component with a symbolic link between a security check and subsequent file operations, an attacker can redirect file access control list operations. This occurs when privileged processes invoke `getfacl` or `setfacl` over an attacker-controlled path, potentially leading to local privilege escalation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 6.3,
              "exploitabilityScore": 1.1,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-54370",
            "epss": 0.00088,
            "percentile": 0.00477,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-54370",
            "cwe": "CWE-367",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.4.0-1.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.4.0-1.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42736",
            "link": "https://access.redhat.com/errata/RHSA-2026:42736"
          }
        ],
        "risk": 0.04971999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-54370",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-54370",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5",
            "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1",
            "https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"
          ],
          "description": "acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.",
          "cvss": [
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 7.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 6.3,
                "exploitabilityScore": 1.1,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-54370",
              "epss": 0.00088,
              "percentile": 0.00477,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-54370",
              "cwe": "CWE-367",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "acl",
              "version": "0:2.3.1-4.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-54370",
            "versionConstraint": "< 0:2.4.0-1.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.4.0-1.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "2cbc02d73c9fa253",
        "name": "acl",
        "version": "2.3.1-4.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:acl:2.3.1-4.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:acl:acl:2.3.1-4.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/acl@2.3.1-4.el9?arch=x86_64&distro=rhel-9.7&upstream=acl-2.3.1-4.el9.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-54370",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-54370",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Medium",
        "urls": [],
        "description": "A time-of-check to time-of-use (TOCTOU) race condition vulnerability was found in `acl`. By replacing a pathname component with a symbolic link between a security check and subsequent file operations, an attacker can redirect file access control list operations. This occurs when privileged processes invoke `getfacl` or `setfacl` over an attacker-controlled path, potentially leading to local privilege escalation.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 6.3,
              "exploitabilityScore": 1.1,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-54370",
            "epss": 0.00088,
            "percentile": 0.00477,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-54370",
            "cwe": "CWE-367",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "0:2.4.0-1.el9_8"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "0:2.4.0-1.el9_8",
              "date": "2026-07-22",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [
          {
            "id": "RHSA-2026:42736",
            "link": "https://access.redhat.com/errata/RHSA-2026:42736"
          }
        ],
        "risk": 0.04971999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-54370",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-54370",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5",
            "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1",
            "https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"
          ],
          "description": "acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.",
          "cvss": [
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 7.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 6.3,
                "exploitabilityScore": 1.1,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-54370",
              "epss": 0.00088,
              "percentile": 0.00477,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-54370",
              "cwe": "CWE-367",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "acl",
              "version": "2.3.1-4.el9"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-54370",
            "versionConstraint": "< 0:2.4.0-1.el9_8 (rpm)"
          },
          "fix": {
            "suggestedVersion": "0:2.4.0-1.el9_8"
          }
        }
      ],
      "artifact": {
        "id": "efaae8c603855dcd",
        "name": "libacl",
        "version": "2.3.1-4.el9",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:libacl:libacl:2.3.1-4.el9:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libacl:2.3.1-4.el9:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64&distro=rhel-9.7&upstream=acl-2.3.1-4.el9.src.rpm",
        "upstreams": [
          {
            "name": "acl",
            "version": "2.3.1-4.el9"
          }
        ],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-5917",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2025-5917",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 2.8,
              "exploitabilityScore": 1.4,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-5917",
            "epss": 0.00165,
            "percentile": 0.06137,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-5917",
            "cwe": "CWE-787",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04785
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-5917",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-5917",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2025-5917",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2370874",
            "https://github.com/libarchive/libarchive/pull/2588",
            "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
          ],
          "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 1.4,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.8,
                "exploitabilityScore": 1.4,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-5917",
              "epss": 0.00165,
              "percentile": 0.06137,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-5917",
              "cwe": "CWE-787",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-5917",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-57062",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-57062",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw in GnuPG's gpgsm component improperly handles the Cryptographic Message Syntax (CMS) format for AES-GCM. By accepting an authentication tag length of 4 bytes instead of the required 12 bytes, this vulnerability allows for a low-impact data integrity issue where the cryptographic validity of messages could be compromised.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "metrics": {
              "baseScore": 2.9,
              "exploitabilityScore": 1.5,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-57062",
            "epss": 0.00142,
            "percentile": 0.03975,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-57062",
            "cwe": "CWE-1284",
            "source": "cve@mitre.org",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04189
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-57062",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-57062",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://blog.calif.io/p/how-to-format-a-ciphertext",
            "https://www.gnupg.org/download/"
          ],
          "description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
          "cvss": [
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-57062",
              "epss": 0.00142,
              "percentile": 0.03975,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-57062",
              "cwe": "CWE-1284",
              "source": "cve@mitre.org",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "gnupg2",
              "version": "0:2.3.3-5.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-57062",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "6612ed205a98e91d",
        "name": "gnupg2",
        "version": "2.3.3-5.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPLv3+"
        ],
        "cpes": [
          "cpe:2.3:a:gnupg2:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=rhel-9.7&upstream=gnupg2-2.3.3-5.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-1485",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-1485",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 2.8,
              "exploitabilityScore": 1.4,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-1485",
            "epss": 0.00139,
            "percentile": 0.0369,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-1485",
            "cwe": "CWE-124",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04031
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-1485",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-1485",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/security/cve/CVE-2026-1485",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2433325",
            "https://gitlab.gnome.org/GNOME/glib/-/issues/3871"
          ],
          "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.8,
                "exploitabilityScore": 1.4,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-1485",
              "epss": 0.00139,
              "percentile": 0.0369,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-1485",
              "cwe": "CWE-124",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "glib2",
              "version": "0:2.68.4-18.el9_7.1"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-1485",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "30f092785d030af5",
        "name": "glib2",
        "version": "2.68.4-18.el9_7.1",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "LGPLv2+"
        ],
        "cpes": [
          "cpe:2.3:a:redhat:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*",
          "cpe:2.3:a:glib2:glib2:2.68.4-18.el9_7.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/glib2@2.68.4-18.el9_7.1?arch=x86_64&distro=rhel-9.7&upstream=glib2-2.68.4-18.el9_7.1.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-16517",
        "dataSource": "https://access.redhat.com/security/cve/CVE-2026-16517",
        "namespace": "redhat:distro:redhat:9",
        "severity": "Low",
        "urls": [],
        "description": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.",
        "cvss": [
          {
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 2.9,
              "exploitabilityScore": 1.5,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-16517",
            "epss": 0.00078,
            "percentile": 0.00175,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-16517",
            "cwe": "CWE-190",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.02301
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-16517",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-16517",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:43818",
            "https://access.redhat.com/security/cve/CVE-2026-16517",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2505492"
          ],
          "description": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-16517",
              "epss": 0.00078,
              "percentile": 0.00175,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-16517",
              "cwe": "CWE-190",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "rpm-matcher",
          "searchedBy": {
            "distro": {
              "type": "redhat",
              "version": "9.7"
            },
            "package": {
              "name": "libarchive",
              "version": "0:3.5.3-9.el9_7"
            },
            "namespace": "redhat:distro:redhat:9"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-16517",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca6753ae0456f1b8",
        "name": "libarchive",
        "version": "3.5.3-9.el9_7",
        "type": "rpm",
        "locations": [
          {
            "path": "/var/lib/rpm/rpmdb.sqlite",
            "layerID": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
            "accessPath": "/var/lib/rpm/rpmdb.sqlite",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [
          "BSD"
        ],
        "cpes": [
          "cpe:2.3:a:libarchive:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*",
          "cpe:2.3:a:redhat:libarchive:3.5.3-9.el9_7:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=rhel-9.7&upstream=libarchive-3.5.3-9.el9_7.src.rpm",
        "upstreams": [],
        "metadataType": "RpmMetadata",
        "metadata": {
          "epoch": null,
          "modularityLabel": "",
          "architecture": "x86_64"
        }
      }
    }
  ],
  "source": {
    "type": "image",
    "target": {
      "userInput": "ghcr.io/telemetryforge/agent:26.4.3",
      "imageID": "sha256:177356b0ff8a3eb24f6022eb370570c514c21a55b1f2af9cc70d5eb8e2fb2acc",
      "manifestDigest": "sha256:a33e7e6ecdcb3f3f3393a486fde13ba48f4359570499ef83b2b658761dc610e2",
      "mediaType": "application/vnd.docker.distribution.manifest.v2+json",
      "tags": [
        "ghcr.io/telemetryforge/agent:26.4.3"
      ],
      "imageSize": 188537772,
      "layers": [
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:5ae199e355f6327e92a77defe42d08e438b66467b478b8f295e1ead3371aaf16",
          "size": 105356808
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:6dad16940a7e86ce80af6a3491457736c0b7459d2dc2203f2427bdfa3c7613fc",
          "size": 56376258
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:a7d6f3535a7abdc80b5ebcd12d3febb5ef6526d57aa371a3750bfa1835cd5d5d",
          "size": 10174
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:2d273d535b7da9d16dbde5bb0fa63d2f9bbc834b438158d8ed9753117a321771",
          "size": 8222
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:0c658a60a2c73576a669770f56825b08907c2b55033b7d4ff38583692ad88d4f",
          "size": 20619255
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:1c6afe7b85ab7c40f6b0796d07fdc957024fa177c6d9c4c4bfdc2bf316fd0f12",
          "size": 1731184
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:89be35095797e82c8f6668ea8e30503f4f040754c428c3272a25bb558944bc7b",
          "size": 1111008
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:cf468d85b6716f0c7b61ba4c373cc7f842225aa6626ca43604a31d6fd076d80f",
          "size": 16337
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:917519ae0941d0b21cf2c0272ead41e75814ef2c962738a4e0565602788ee4c4",
          "size": 0
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:284ada112fdd39131ce2464b68cae710dc45e89cbf88744fd9b25a77a0ea1a24",
          "size": 581
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:e31c220a2208050abda7c36cd3650fddd20aadea6e675baa3f0692e27bfcd83f",
          "size": 581
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:19f3a9dec8d4ac75c03a8657b27a33440aa7fc78e47e13124f2ee89c1bf65155",
          "size": 418674
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:817f28454c551476bfaca24e5b6c83366067ae942eaf4d7d36aa62152a9347e1",
          "size": 2888690
        }
      ],
      "manifest": "eyJzY2hlbWFWZXJzaW9uIjoyLCJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmRpc3RyaWJ1dGlvbi5tYW5pZmVzdC52Mitqc29uIiwiY29uZmlnIjp7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuY29udGFpbmVyLmltYWdlLnYxK2pzb24iLCJzaXplIjoxMjg2OSwiZGlnZXN0Ijoic2hhMjU2OjE3NzM1NmIwZmY4YTNlYjI0ZjYwMjJlYjM3MDU3MGM1MTRjMjFhNTViMWYyYWY5Y2M3MGQ1ZWI4ZTJmYjJhY2MifSwibGF5ZXJzIjpbeyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6MTA3MDgzMjY0LCJkaWdlc3QiOiJzaGEyNTY6NWFlMTk5ZTM1NWY2MzI3ZTkyYTc3ZGVmZTQyZDA4ZTQzOGI2NjQ2N2I0NzhiOGYyOTVlMWVhZDMzNzFhYWYxNiJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjU4MjA5MjgwLCJkaWdlc3QiOiJzaGEyNTY6NmRhZDE2OTQwYTdlODZjZTgwYWY2YTM0OTE0NTc3MzZjMGI3NDU5ZDJkYzIyMDNmMjQyN2JkZmEzYzc2MTNmYyJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjEyMjg4LCJkaWdlc3QiOiJzaGEyNTY6YTdkNmYzNTM1YTdhYmRjODBiNWViY2QxMmQzZmViYjVlZjY1MjZkNTdhYTM3MWEzNzUwYmZhMTgzNWNkNWQ1ZCJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjEwMjQwLCJkaWdlc3QiOiJzaGEyNTY6MmQyNzNkNTM1YjdkYTlkMTZkYmRlNWJiMGZhNjNkMmY5YmJjODM0YjQzODE1OGQ4ZWQ5NzUzMTE3YTMyMTc3MSJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjIwNjQ0ODY0LCJkaWdlc3QiOiJzaGEyNTY6MGM2NThhNjBhMmM3MzU3NmE2Njk3NzBmNTY4MjViMDg5MDdjMmI1NTAzM2I3ZDRmZjM4NTgzNjkyYWQ4OGQ0ZiJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjE3MzQ2NTYsImRpZ2VzdCI6InNoYTI1NjoxYzZhZmU3Yjg1YWI3YzQwZjZiMDc5NmQwN2ZkYzk1NzAyNGZhMTc3YzZkOWM0YzRiZmRjMmJmMzE2ZmQwZjEyIn0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6MTExNDExMiwiZGlnZXN0Ijoic2hhMjU2Ojg5YmUzNTA5NTc5N2U4MmM4ZjY2NjhlYThlMzA1MDNmNGYwNDA3NTRjNDI4YzMyNzJhMjViYjU1ODk0NGJjN2IifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjoyNTYwMCwiZGlnZXN0Ijoic2hhMjU2OmNmNDY4ZDg1YjY3MTZmMGM3YjYxYmE0YzM3M2NjN2Y4NDIyMjVhYTY2MjZjYTQzNjA0YTMxZDZmZDA3NmQ4MGYifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjoyNTYwLCJkaWdlc3QiOiJzaGEyNTY6OTE3NTE5YWUwOTQxZDBiMjFjZjJjMDI3MmVhZDQxZTc1ODE0ZWYyYzk2MjczOGE0ZTA1NjU2MDI3ODhlZTRjNCJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjQwOTYsImRpZ2VzdCI6InNoYTI1NjoyODRhZGExMTJmZGQzOTEzMWNlMjQ2NGI2OGNhZTcxMGRjNDVlODljYmY4ODc0NGZkOWIyNWE3N2EwZWExYTI0In0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6MzU4NCwiZGlnZXN0Ijoic2hhMjU2OmUzMWMyMjBhMjIwODA1MGFiZGE3YzM2Y2QzNjUwZmRkZDIwYWFkZWE2ZTY3NWJhYTNmMDY5MmUyN2JmY2Q4M2YifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjo0MjM0MjQsImRpZ2VzdCI6InNoYTI1NjoxOWYzYTlkZWM4ZDRhYzc1YzAzYTg2NTdiMjdhMzM0NDBhYTdmYzc4ZTQ3ZTEzMTI0ZjJlZTg5YzFiZjY1MTU1In0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6MjkwNTA4OCwiZGlnZXN0Ijoic2hhMjU2OjgxN2YyODQ1NGM1NTE0NzZiZmFjYTI0ZTViNmM4MzM2NjA2N2FlOTQyZWFmNGQ3ZDM2YWE2MjE1MmE5MzQ3ZTEifV19",
      "config": "eyJhcmNoaXRlY3R1cmUiOiJhbWQ2NCIsImNvbmZpZyI6eyJVc2VyIjoiOTg3NiIsIkV4cG9zZWRQb3J0cyI6eyIyMDIwL3RjcCI6e319LCJFbnYiOlsiUEFUSD0vdXNyL2xvY2FsL3NiaW46L3Vzci9sb2NhbC9iaW46L3Vzci9zYmluOi91c3IvYmluOi9zYmluOi9iaW4iLCJjb250YWluZXI9b2NpIiwiRkxVRU5UQklUX1ZFUlNJT049IiwiVEVMRU1FVFJZX0ZPUkdFX0FHRU5UX1ZFUlNJT049MjYuNC4zIl0sIkVudHJ5cG9pbnQiOlsiL2ZsdWVudC1iaXQvYmluL2ZsdWVudC1iaXQiXSwiQ21kIjpbIi9mbHVlbnQtYml0L2Jpbi9mbHVlbnQtYml0IiwiLWMiLCIvZmx1ZW50LWJpdC9ldGMvZmx1ZW50LWJpdC5jb25mIl0sIldvcmtpbmdEaXIiOiIvIiwiTGFiZWxzIjp7ImFyY2hpdGVjdHVyZSI6Ing4Nl82NCIsImJ1aWxkLWRhdGUiOiIyMDI2MDQyMS0xMDMwNTEiLCJjb20ucmVkaGF0LmNvbXBvbmVudCI6InViaTktbWluaW1hbC1jb250YWluZXIiLCJjb20ucmVkaGF0LmxpY2Vuc2VfdGVybXMiOiJodHRwczovL3d3dy5yZWRoYXQuY29tL2VuL2Fib3V0L3JlZC1oYXQtZW5kLXVzZXItbGljZW5zZS1hZ3JlZW1lbnRzI1VCSSIsImNwZSI6ImNwZTovYTpyZWRoYXQ6ZW50ZXJwcmlzZV9saW51eDo5OjphcHBzdHJlYW0iLCJkZXNjcmlwdGlvbiI6IlRlbGVtZXRyeSBGb3JnZSBBZ2VudCBpcyBhIHN0YWJsZSwgc2VjdXJlIGJ5IGRlZmF1bHQsIE9TUyAoQXBhY2hlLWxpY2Vuc2VkKSBkb3duc3RyZWFtIGRpc3RyaWJ1dGlvbiBvZiBGbHVlbnQgQml0IHdpdGggcHJlZGljdGFibGUgcmVsZWFzZXMgYW5kIGxvbmctdGVybSBzdXBwb3J0ZWQgdmVyc2lvbnMgZm9yIDI0IG1vbnRocy4iLCJkaXN0cmlidXRpb24tc2NvcGUiOiJwdWJsaWMiLCJpby5idWlsZGFoLnZlcnNpb24iOiIxLjQyLjIiLCJpby5rOHMuZGVzY3JpcHRpb24iOiJUZWxlbWV0cnkgRm9yZ2UgQWdlbnQgaXMgYSBzdGFibGUsIHNlY3VyZSBieSBkZWZhdWx0LCBPU1MgKEFwYWNoZS1saWNlbnNlZCkgZG93bnN0cmVhbSBkaXN0cmlidXRpb24gb2YgRmx1ZW50IEJpdCB3aXRoIHByZWRpY3RhYmxlIHJlbGVhc2VzIGFuZCBsb25nLXRlcm0gc3VwcG9ydGVkIHZlcnNpb25zIGZvciAyNCBtb250aHMuIiwiaW8uazhzLmRpc3BsYXktbmFtZSI6IlRlbGVtZXRyeSBGb3JnZSBBZ2VudCIsImlvLm9wZW5zaGlmdC5leHBvc2Utc2VydmljZXMiOiIiLCJpby5vcGVuc2hpZnQudGFncyI6Im9ic2VydmFiaWxpdHksbG9nZ2luZyxsb2ctYWdncmVnYXRpb24sdGVsZW1ldHJ5Zm9yZ2UsZmx1ZW50LWJpdCIsIm1haW50YWluZXIiOiJUZWxlbWV0cnkgRm9yZ2UgdmlhIGluZm9AdGVsZW1ldHJ5Zm9yZ2UuaW8iLCJuYW1lIjoiVGVsZW1ldHJ5IEZvcmdlIEFnZW50Iiwib3JnLm9wZW5jb250YWluZXJzLmltYWdlLmNyZWF0ZWQiOiIyMDI2LTA0LTIxVDEwOjMwOjUxLjY1NVoiLCJvcmcub3BlbmNvbnRhaW5lcnMuaW1hZ2UuZGVzY3JpcHRpb24iOiJUZWxlbWV0cnkgRm9yZ2UgQWdlbnQgaXMgYSBzdGFibGUsIHNlY3VyZSBieSBkZWZhdWx0LCBPU1MgKEFwYWNoZS1saWNlbnNlZCkgZG93bnN0cmVhbSBkaXN0cmlidXRpb24gb2YgRmx1ZW50IEJpdCB3aXRoIHByZWRpY3RhYmxlIHJlbGVhc2VzIGFuZCBsb25nLXRlcm0gc3VwcG9ydGVkIHZlcnNpb25zIGZvciAyNCBtb250aHMuIiwib3JnLm9wZW5jb250YWluZXJzLmltYWdlLmxpY2Vuc2VzIjoiIiwib3JnLm9wZW5jb250YWluZXJzLmltYWdlLnJldmlzaW9uIjoiYzhjMjJjNjZlNjRjYTcyY2Y3ZGRjODAwNGRjMzFhZTcwNTBlNjQ2YiIsIm9yZy5vcGVuY29udGFpbmVycy5pbWFnZS5zb3VyY2UiOiJodHRwczovL2dpdGh1Yi5jb20vdGVsZW1ldHJ5Zm9yZ2UvYWdlbnQiLCJvcmcub3BlbmNvbnRhaW5lcnMuaW1hZ2UudGl0bGUiOiJhZ2VudCIsIm9yZy5vcGVuY29udGFpbmVycy5pbWFnZS51cmwiOiJodHRwczovL2dpdGh1Yi5jb20vdGVsZW1ldHJ5Zm9yZ2UvYWdlbnQiLCJvcmcub3BlbmNvbnRhaW5lcnMuaW1hZ2UudmVyc2lvbiI6InYyNi40LjMiLCJyZWxlYXNlIjoiMTc3NjY0NTk0MSIsInN1bW1hcnkiOiJUZWxlbWV0cnkgRm9yZ2UgQWdlbnQgaXMgYW4gRW50ZXJwcmlzZSBoYXJkZW5lZCB2ZXJzaW9uIG9mIEZsdWVudCBCaXQiLCJ1cmwiOiJodHRwczovL3RlbGVtZXRyeWZvcmdlLmlvIiwidmNzLXJlZiI6IjBiYzYxYTI3NGVkZGRjMTQ2N2MyYWQwZGRjMzEzOTU0M2M0ZGE0ZGEiLCJ2Y3MtdHlwZSI6ImdpdCIsInZlbmRvciI6IlRlbGVtZXRyeSBGb3JnZSBhdCBodHRwczovL3RlbGVtZXRyeWZvcmdlLmlvIiwidmVyc2lvbiI6IjI2LjQuMyJ9LCJBcmdzRXNjYXBlZCI6dHJ1ZX0sImNyZWF0ZWQiOiIyMDI2LTA0LTIxVDEwOjM5OjI3LjM2NTU2MzczNVoiLCJoaXN0b3J5IjpbeyJjcmVhdGVkIjoiMjAyNi0wNC0yMFQwMDo0NzowNS4yMjYwNjM1NTJaIiwiY3JlYXRlZF9ieSI6Ii9iaW4vc2ggLWMgIyhub3ApIExBQkVMIG1haW50YWluZXI9XCJSZWQgSGF0LCBJbmMuXCIiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMFQwMDo0NzowNS4yNDY3NzA3MTFaIiwiY3JlYXRlZF9ieSI6Ii9iaW4vc2ggLWMgIyhub3ApIExBQkVMIHZlbmRvcj1cIlJlZCBIYXQsIEluYy5cIiIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIwVDAwOjQ3OjA1LjI2OTU3MDA0NVoiLCJjcmVhdGVkX2J5IjoiL2Jpbi9zaCAtYyAjKG5vcCkgTEFCRUwgdXJsPVwiaHR0cHM6Ly9jYXRhbG9nLnJlZGhhdC5jb20vZW4vc2VhcmNoP3NlYXJjaFR5cGU9Y29udGFpbmVyc1wiIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjBUMDA6NDc6MDUuMzAzODAxMTU2WiIsImNyZWF0ZWRfYnkiOiIvYmluL3NoIC1jICMobm9wKSBMQUJFTCBjb20ucmVkaGF0LmNvbXBvbmVudD1cInViaTktbWluaW1hbC1jb250YWluZXJcIiAgICAgICBuYW1lPVwidWJpOS91YmktbWluaW1hbFwiICAgICAgIHZlcnNpb249XCI5LjdcIiAgICAgICBjcGU9XCJjcGU6L2E6cmVkaGF0OmVudGVycHJpc2VfbGludXg6OTo6YXBwc3RyZWFtXCIgICAgICAgZGlzdHJpYnV0aW9uLXNjb3BlPVwicHVibGljXCIiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMFQwMDo0NzowNS4zMjM2MjAxODZaIiwiY3JlYXRlZF9ieSI6Ii9iaW4vc2ggLWMgIyhub3ApIExBQkVMIGNvbS5yZWRoYXQubGljZW5zZV90ZXJtcz1cImh0dHBzOi8vd3d3LnJlZGhhdC5jb20vZW4vYWJvdXQvcmVkLWhhdC1lbmQtdXNlci1saWNlbnNlLWFncmVlbWVudHMjVUJJXCIiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMFQwMDo0NzowNS4zNDQ3NzQ4NDRaIiwiY3JlYXRlZF9ieSI6Ii9iaW4vc2ggLWMgIyhub3ApIExBQkVMIHN1bW1hcnk9XCJQcm92aWRlcyB0aGUgbGF0ZXN0IHJlbGVhc2Ugb2YgdGhlIG1pbmltYWwgUmVkIEhhdCBVbml2ZXJzYWwgQmFzZSBJbWFnZSA5LlwiIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjBUMDA6NDc6MDUuMzYzNjQyNzMzWiIsImNyZWF0ZWRfYnkiOiIvYmluL3NoIC1jICMobm9wKSBMQUJFTCBkZXNjcmlwdGlvbj1cIlRoZSBVbml2ZXJzYWwgQmFzZSBJbWFnZSBNaW5pbWFsIGlzIGEgc3RyaXBwZWQgZG93biBpbWFnZSB0aGF0IHVzZXMgbWljcm9kbmYgYXMgYSBwYWNrYWdlIG1hbmFnZXIuIFRoaXMgYmFzZSBpbWFnZSBpcyBmcmVlbHkgcmVkaXN0cmlidXRhYmxlLCBidXQgUmVkIEhhdCBvbmx5IHN1cHBvcnRzIFJlZCBIYXQgdGVjaG5vbG9naWVzIHRocm91Z2ggc3Vic2NyaXB0aW9ucyBmb3IgUmVkIEhhdCBwcm9kdWN0cy4gVGhpcyBpbWFnZSBpcyBtYWludGFpbmVkIGJ5IFJlZCBIYXQgYW5kIHVwZGF0ZWQgcmVndWxhcmx5LlwiIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjBUMDA6NDc6MDUuMzgzNjgyNzY3WiIsImNyZWF0ZWRfYnkiOiIvYmluL3NoIC1jICMobm9wKSBMQUJFTCBpby5rOHMuZGVzY3JpcHRpb249XCJUaGUgVW5pdmVyc2FsIEJhc2UgSW1hZ2UgTWluaW1hbCBpcyBhIHN0cmlwcGVkIGRvd24gaW1hZ2UgdGhhdCB1c2VzIG1pY3JvZG5mIGFzIGEgcGFja2FnZSBtYW5hZ2VyLiBUaGlzIGJhc2UgaW1hZ2UgaXMgZnJlZWx5IHJlZGlzdHJpYnV0YWJsZSwgYnV0IFJlZCBIYXQgb25seSBzdXBwb3J0cyBSZWQgSGF0IHRlY2hub2xvZ2llcyB0aHJvdWdoIHN1YnNjcmlwdGlvbnMgZm9yIFJlZCBIYXQgcHJvZHVjdHMuIFRoaXMgaW1hZ2UgaXMgbWFpbnRhaW5lZCBieSBSZWQgSGF0IGFuZCB1cGRhdGVkIHJlZ3VsYXJseS5cIiIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIwVDAwOjQ3OjA1LjQwMzE4OTg0WiIsImNyZWF0ZWRfYnkiOiIvYmluL3NoIC1jICMobm9wKSBMQUJFTCBpby5rOHMuZGlzcGxheS1uYW1lPVwiUmVkIEhhdCBVbml2ZXJzYWwgQmFzZSBJbWFnZSA5IE1pbmltYWxcIiIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIwVDAwOjQ3OjA1LjQyMTI3ODk2MloiLCJjcmVhdGVkX2J5IjoiL2Jpbi9zaCAtYyAjKG5vcCkgTEFCRUwgaW8ub3BlbnNoaWZ0LmV4cG9zZS1zZXJ2aWNlcz1cIlwiIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjBUMDA6NDc6MDUuNDQwNTMxNjY5WiIsImNyZWF0ZWRfYnkiOiIvYmluL3NoIC1jICMobm9wKSBMQUJFTCBpby5vcGVuc2hpZnQudGFncz1cIm1pbmltYWwgcmhlbDlcIiIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIwVDAwOjQ3OjA1LjQ2MDEyMjE2M1oiLCJjcmVhdGVkX2J5IjoiL2Jpbi9zaCAtYyAjKG5vcCkgRU5WIGNvbnRhaW5lciBvY2kiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMFQwMDo0NzowNi4wMDU1ODkwMzJaIiwiY3JlYXRlZF9ieSI6Ii9iaW4vc2ggLWMgIyhub3ApIENPUFkgZGlyOjk1ZDE3YzU3ZWY0MGE1ZGJhNzk3MDRlOTJiOWM1NTI3ZDNhY2IzMjI2MzY0ZTQyYzBkNDE3NjM0NzFlNjFjZTYgaW4gLyAgICAgICIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIwVDAwOjQ3OjA2LjEwMjc1MzI0N1oiLCJjcmVhdGVkX2J5IjoiL2Jpbi9zaCAtYyAjKG5vcCkgQ09QWSBmaWxlOjEzNzY3MDI1MTVkNTk2ZjQxNGUzYWE0OTRlMGRhYTZkNDA4YTZkMjQ3NWM0YWVjYTk2YmY5MzkyZjUyODdmNjkgaW4gL2V0Yy95dW0ucmVwb3MuZC8uICAgICAgIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjBUMDA6NDc6MDYuMTIzMjQyMjQxWiIsImNyZWF0ZWRfYnkiOiIvYmluL3NoIC1jICMobm9wKSBDTUQgW1wiL2Jpbi9iYXNoXCJdIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjBUMDA6NDc6MDYuMjIyMzY3NTI5WiIsImNyZWF0ZWRfYnkiOiIvYmluL3NoIC1jICMobm9wKSBDT1BZIGZpbGU6OTM1ODNhOWViYmFlZmYxZTM2YjQ4ODIwYjY0N2VlYTFlZWY1MjNmNjYyN2RhY2ZiMGIyMWFmNzlmNWE0MWIzNSBpbiAvdXNyL3NoYXJlL2J1aWxkaW5mby9jb250ZW50LXNldHMuanNvbiAgICAgICIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIwVDAwOjQ3OjA2LjMyMDUxODU0NVoiLCJjcmVhdGVkX2J5IjoiL2Jpbi9zaCAtYyAjKG5vcCkgQ09QWSBmaWxlOjkzNTgzYTllYmJhZWZmMWUzNmI0ODgyMGI2NDdlZWExZWVmNTIzZjY2MjdkYWNmYjBiMjFhZjc5ZjVhNDFiMzUgaW4gL3Jvb3QvYnVpbGRpbmZvL2NvbnRlbnRfbWFuaWZlc3RzL2NvbnRlbnQtc2V0cy5qc29uICAgICAgIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjBUMDA6NDc6MDYuNDE4ODU2ODg2WiIsImNyZWF0ZWRfYnkiOiIvYmluL3NoIC1jICMobm9wKSBDT1BZIGZpbGU6NDBiODIxYjQ0Mzk1MjQ4NzdmNGMwMWE2NjBkOTY4NTI2MmYyZjAwOGY2YzZkZTliYThiNjkwYzdlMjc0MDMwMyBpbiAvdXNyL3NoYXJlL2J1aWxkaW5mby9sYWJlbHMuanNvbiAgICAgICIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIwVDAwOjQ3OjA2LjUxNjUzNjM3MloiLCJjcmVhdGVkX2J5IjoiL2Jpbi9zaCAtYyAjKG5vcCkgQ09QWSBmaWxlOjQwYjgyMWI0NDM5NTI0ODc3ZjRjMDFhNjYwZDk2ODUyNjJmMmYwMDhmNmM2ZGU5YmE4YjY5MGM3ZTI3NDAzMDMgaW4gL3Jvb3QvYnVpbGRpbmZvL2xhYmVscy5qc29uICAgICAgIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjBUMDA6NDc6MDYuODE0MzQyNDU1WiIsImNyZWF0ZWRfYnkiOiIvYmluL3NoIC1jICMobm9wKSBMQUJFTCBcImFyY2hpdGVjdHVyZVwiPVwieDg2XzY0XCIgXCJ2Y3MtdHlwZVwiPVwiZ2l0XCIgXCJ2Y3MtcmVmXCI9XCIwYmM2MWEyNzRlZGRkYzE0NjdjMmFkMGRkYzMxMzk1NDNjNGRhNGRhXCIgXCJvcmcub3BlbmNvbnRhaW5lcnMuaW1hZ2UucmV2aXNpb25cIj1cIjBiYzYxYTI3NGVkZGRjMTQ2N2MyYWQwZGRjMzEzOTU0M2M0ZGE0ZGFcIiBcImJ1aWxkLWRhdGVcIj1cIjIwMjYtMDQtMjBUMDA6NDY6NDhaXCIgXCJvcmcub3BlbmNvbnRhaW5lcnMuaW1hZ2UuY3JlYXRlZFwiPVwiMjAyNi0wNC0yMFQwMDo0Njo0OFpcIiBcInJlbGVhc2VcIj1cIjE3NzY2NDU5NDFcIm9yZy5vcGVuY29udGFpbmVycy5pbWFnZS5yZXZpc2lvbj0wYmM2MWEyNzRlZGRkYzE0NjdjMmFkMGRkYzMxMzk1NDNjNGRhNGRhLG9yZy5vcGVuY29udGFpbmVycy5pbWFnZS5jcmVhdGVkPTIwMjYtMDQtMjBUMDA6NDY6NDhaIn0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMVQxMDozMToxMS42ODcyMzY4WiIsImNyZWF0ZWRfYnkiOiJSVU4gL2Jpbi9zaCAtYyBtaWNyb2RuZiB1cGRhdGUgLXkgXHUwMDI2XHUwMDI2IG1pY3JvZG5mIGluc3RhbGwgLXkgb3BlbnNzbCBsaWJ5YW1sIGN5cnVzLXNhc2wgXHUwMDI2XHUwMDI2IG1pY3JvZG5mIGNsZWFuIGFsbCAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIxVDEwOjMxOjExLjc0ODkzMzMzOFoiLCJjcmVhdGVkX2J5IjoiRVhQT1NFIFsyMDIwL3RjcF0iLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIxVDEwOjMxOjExLjc0ODkzMzMzOFoiLCJjcmVhdGVkX2J5IjoiRU5UUllQT0lOVCBbXCIvZmx1ZW50LWJpdC9iaW4vZmx1ZW50LWJpdFwiXSIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjFUMTA6MzE6MTEuNzQ4OTMzMzM4WiIsImNyZWF0ZWRfYnkiOiJDTUQgW1wiL2ZsdWVudC1iaXQvYmluL2ZsdWVudC1iaXRcIiBcIi1jXCIgXCIvZmx1ZW50LWJpdC9ldGMvZmx1ZW50LWJpdC5jb25mXCJdIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMVQxMDozMToxMS43NDg5MzMzMzhaIiwiY3JlYXRlZF9ieSI6IkNPUFkgbGljZW5zZXMvKiAvbGljZW5zZXMvICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjFUMTA6MzE6MTEuODQxNDc5MzA3WiIsImNyZWF0ZWRfYnkiOiJDT1BZIFJFQURNRS5tZCAvaGVscC4xICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjFUMTA6Mzk6MjYuMzcyNTM2NzI3WiIsImNyZWF0ZWRfYnkiOiJDT1BZIC9mbHVlbnQtYml0IC9mbHVlbnQtYml0ICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjFUMTA6Mzk6MjYuNDE3NTQ0Njg5WiIsImNyZWF0ZWRfYnkiOiJDT1BZIC91c3IvbG9jYWwvbGliNjQvbGliZ2l0Mi5zby4qLiouKiAvdXNyL2xvY2FsL2xpYjY0LyAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIxVDEwOjM5OjI2LjQ5ODY2MTcwM1oiLCJjcmVhdGVkX2J5IjoiQ09QWSAvdXNyL2xvY2FsL2xpYi9saWJzc2gyLnNvLiouKi4qIC91c3IvbG9jYWwvbGliLyAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIxVDEwOjM5OjI2LjY3OTkwMjYyMVoiLCJjcmVhdGVkX2J5IjoiUlVOIC9iaW4vc2ggLWMgZWNobyBcIi91c3IvbG9jYWwvbGliNjRcIiBcdTAwM2UgL2V0Yy9sZC5zby5jb25mLmQvbG9jYWwtbGlicy5jb25mIFx1MDAyNlx1MDAyNiAgICAgZWNobyBcIi91c3IvbG9jYWwvbGliXCIgXHUwMDNlXHUwMDNlIC9ldGMvbGQuc28uY29uZi5kL2xvY2FsLWxpYnMuY29uZiBcdTAwMjZcdTAwMjYgICAgIGxkY29uZmlnICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjFUMTA6Mzk6MjYuNzcxMDcxNDM5WiIsImNyZWF0ZWRfYnkiOiJSVU4gL2Jpbi9zaCAtYyBta2RpciAtcCAvb3B0L3RlbGVtZXRyeWZvcmdlLWFnZW50L2V0YyAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIxVDEwOjM5OjI2Ljg2OTI4MTY5OVoiLCJjcmVhdGVkX2J5IjoiQ09QWSBjb25maWcvIC9vcHQvdGVsZW1ldHJ5Zm9yZ2UtYWdlbnQvZXRjLyAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIxVDEwOjM5OjI2Ljg5ODE0MTkyMVoiLCJjcmVhdGVkX2J5IjoiQ09QWSBjb25maWcvIC9mbHVlbnQtYml0L2V0Yy8gIyBidWlsZGtpdCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIn0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMVQxMDozOToyNy4wMzc0NTYyODJaIiwiY3JlYXRlZF9ieSI6IlJVTiAvYmluL3NoIC1jIC9mbHVlbnQtYml0L2Jpbi9mbHVlbnQtYml0IC1KIFx1MDAzZSAvZmx1ZW50LWJpdC9ldGMvc2NoZW1hLmpzb24gXHUwMDI2XHUwMDI2ICAgICAvZmx1ZW50LWJpdC9iaW4vZmx1ZW50LWJpdCAtSiBcdTAwM2UgL29wdC90ZWxlbWV0cnlmb3JnZS1hZ2VudC9ldGMvc2NoZW1hLmpzb24gIyBidWlsZGtpdCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIn0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMVQxMDozOToyNy4wMzc0NTYyODJaIiwiY3JlYXRlZF9ieSI6IkFSRyBGTFVFTlRfQklUX1ZFUlNJT04iLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIxVDEwOjM5OjI3LjAzNzQ1NjI4MloiLCJjcmVhdGVkX2J5IjoiQVJHIFRFTEVNRVRSWV9GT1JHRV9BR0VOVF9WRVJTSU9OPTI2LjQuMyIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjFUMTA6Mzk6MjcuMDM3NDU2MjgyWiIsImNyZWF0ZWRfYnkiOiJFTlYgRkxVRU5UQklUX1ZFUlNJT049IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMVQxMDozOToyNy4wMzc0NTYyODJaIiwiY3JlYXRlZF9ieSI6IkVOViBURUxFTUVUUllfRk9SR0VfQUdFTlRfVkVSU0lPTj0yNi40LjMiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIxVDEwOjM5OjI3LjAzNzQ1NjI4MloiLCJjcmVhdGVkX2J5IjoiTEFCRUwgdmVuZG9yPVRlbGVtZXRyeSBGb3JnZSBhdCBodHRwczovL3RlbGVtZXRyeWZvcmdlLmlvIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMVQxMDozOToyNy4wMzc0NTYyODJaIiwiY3JlYXRlZF9ieSI6IkxBQkVMIG1haW50YWluZXI9VGVsZW1ldHJ5IEZvcmdlIHZpYSBpbmZvQHRlbGVtZXRyeWZvcmdlLmlvIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMVQxMDozOToyNy4wMzc0NTYyODJaIiwiY3JlYXRlZF9ieSI6IkxBQkVMIG5hbWU9VGVsZW1ldHJ5IEZvcmdlIEFnZW50IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMVQxMDozOToyNy4wMzc0NTYyODJaIiwiY3JlYXRlZF9ieSI6IkxBQkVMIGlvLms4cy5kaXNwbGF5LW5hbWU9VGVsZW1ldHJ5IEZvcmdlIEFnZW50IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMVQxMDozOToyNy4wMzc0NTYyODJaIiwiY3JlYXRlZF9ieSI6IkxBQkVMIHN1bW1hcnk9VGVsZW1ldHJ5IEZvcmdlIEFnZW50IGlzIGFuIEVudGVycHJpc2UgaGFyZGVuZWQgdmVyc2lvbiBvZiBGbHVlbnQgQml0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMVQxMDozOToyNy4wMzc0NTYyODJaIiwiY3JlYXRlZF9ieSI6IkxBQkVMIHVybD1odHRwczovL3RlbGVtZXRyeWZvcmdlLmlvIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wNC0yMVQxMDozOToyNy4wMzc0NTYyODJaIiwiY3JlYXRlZF9ieSI6IkxBQkVMIGlvLm9wZW5zaGlmdC50YWdzPW9ic2VydmFiaWxpdHksbG9nZ2luZyxsb2ctYWdncmVnYXRpb24sdGVsZW1ldHJ5Zm9yZ2UsZmx1ZW50LWJpdCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjFUMTA6Mzk6MjcuMDM3NDU2MjgyWiIsImNyZWF0ZWRfYnkiOiJMQUJFTCB2ZXJzaW9uPTI2LjQuMyIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjFUMTA6Mzk6MjcuMDM3NDU2MjgyWiIsImNyZWF0ZWRfYnkiOiJMQUJFTCBpby5rOHMuZGVzY3JpcHRpb249VGVsZW1ldHJ5IEZvcmdlIEFnZW50IGlzIGEgc3RhYmxlLCBzZWN1cmUgYnkgZGVmYXVsdCwgT1NTIChBcGFjaGUtbGljZW5zZWQpIGRvd25zdHJlYW0gZGlzdHJpYnV0aW9uIG9mIEZsdWVudCBCaXQgd2l0aCBwcmVkaWN0YWJsZSByZWxlYXNlcyBhbmQgbG9uZy10ZXJtIHN1cHBvcnRlZCB2ZXJzaW9ucyBmb3IgMjQgbW9udGhzLiIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDQtMjFUMTA6Mzk6MjcuMzY1NTYzNzM1WiIsImNyZWF0ZWRfYnkiOiJSVU4gfDIgRkxVRU5UX0JJVF9WRVJTSU9OPSBURUxFTUVUUllfRk9SR0VfQUdFTlRfVkVSU0lPTj0yNi40LjMgL2Jpbi9zaCAtYyB1c2VyYWRkIC11IDk4NzYgLW0gLXMgL2Jpbi9mYWxzZSB0ZWxlbWV0cnlmb3JnZS1hZ2VudCAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA0LTIxVDEwOjM5OjI3LjM2NTU2MzczNVoiLCJjcmVhdGVkX2J5IjoiVVNFUiA5ODc2IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX1dLCJvcyI6ImxpbnV4Iiwicm9vdGZzIjp7InR5cGUiOiJsYXllcnMiLCJkaWZmX2lkcyI6WyJzaGEyNTY6NWFlMTk5ZTM1NWY2MzI3ZTkyYTc3ZGVmZTQyZDA4ZTQzOGI2NjQ2N2I0NzhiOGYyOTVlMWVhZDMzNzFhYWYxNiIsInNoYTI1Njo2ZGFkMTY5NDBhN2U4NmNlODBhZjZhMzQ5MTQ1NzczNmMwYjc0NTlkMmRjMjIwM2YyNDI3YmRmYTNjNzYxM2ZjIiwic2hhMjU2OmE3ZDZmMzUzNWE3YWJkYzgwYjVlYmNkMTJkM2ZlYmI1ZWY2NTI2ZDU3YWEzNzFhMzc1MGJmYTE4MzVjZDVkNWQiLCJzaGEyNTY6MmQyNzNkNTM1YjdkYTlkMTZkYmRlNWJiMGZhNjNkMmY5YmJjODM0YjQzODE1OGQ4ZWQ5NzUzMTE3YTMyMTc3MSIsInNoYTI1NjowYzY1OGE2MGEyYzczNTc2YTY2OTc3MGY1NjgyNWIwODkwN2MyYjU1MDMzYjdkNGZmMzg1ODM2OTJhZDg4ZDRmIiwic2hhMjU2OjFjNmFmZTdiODVhYjdjNDBmNmIwNzk2ZDA3ZmRjOTU3MDI0ZmExNzdjNmQ5YzRjNGJmZGMyYmYzMTZmZDBmMTIiLCJzaGEyNTY6ODliZTM1MDk1Nzk3ZTgyYzhmNjY2OGVhOGUzMDUwM2Y0ZjA0MDc1NGM0MjhjMzI3MmEyNWJiNTU4OTQ0YmM3YiIsInNoYTI1NjpjZjQ2OGQ4NWI2NzE2ZjBjN2I2MWJhNGMzNzNjYzdmODQyMjI1YWE2NjI2Y2E0MzYwNGEzMWQ2ZmQwNzZkODBmIiwic2hhMjU2OjkxNzUxOWFlMDk0MWQwYjIxY2YyYzAyNzJlYWQ0MWU3NTgxNGVmMmM5NjI3MzhhNGUwNTY1NjAyNzg4ZWU0YzQiLCJzaGEyNTY6Mjg0YWRhMTEyZmRkMzkxMzFjZTI0NjRiNjhjYWU3MTBkYzQ1ZTg5Y2JmODg3NDRmZDliMjVhNzdhMGVhMWEyNCIsInNoYTI1NjplMzFjMjIwYTIyMDgwNTBhYmRhN2MzNmNkMzY1MGZkZGQyMGFhZGVhNmU2NzViYWEzZjA2OTJlMjdiZmNkODNmIiwic2hhMjU2OjE5ZjNhOWRlYzhkNGFjNzVjMDNhODY1N2IyN2EzMzQ0MGFhN2ZjNzhlNDdlMTMxMjRmMmVlODljMWJmNjUxNTUiLCJzaGEyNTY6ODE3ZjI4NDU0YzU1MTQ3NmJmYWNhMjRlNWI2YzgzMzY2MDY3YWU5NDJlYWY0ZDdkMzZhYTYyMTUyYTkzNDdlMSJdfX0=",
      "repoDigests": [
        "ghcr.io/telemetryforge/agent@sha256:0db9c435a5a84adcaa5a0d535f07029a2a36c7d2b354c2e0faf2b3e51ed12a96"
      ],
      "architecture": "amd64",
      "os": "linux",
      "labels": {
        "architecture": "x86_64",
        "build-date": "20260421-103051",
        "com.redhat.component": "ubi9-minimal-container",
        "com.redhat.license_terms": "https://www.redhat.com/en/about/red-hat-end-user-license-agreements#UBI",
        "cpe": "cpe:/a:redhat:enterprise_linux:9::appstream",
        "description": "Telemetry Forge Agent is a stable, secure by default, OSS (Apache-licensed) downstream distribution of Fluent Bit with predictable releases and long-term supported versions for 24 months.",
        "distribution-scope": "public",
        "io.buildah.version": "1.42.2",
        "io.k8s.description": "Telemetry Forge Agent is a stable, secure by default, OSS (Apache-licensed) downstream distribution of Fluent Bit with predictable releases and long-term supported versions for 24 months.",
        "io.k8s.display-name": "Telemetry Forge Agent",
        "io.openshift.expose-services": "",
        "io.openshift.tags": "observability,logging,log-aggregation,telemetryforge,fluent-bit",
        "maintainer": "Telemetry Forge via info@telemetryforge.io",
        "name": "Telemetry Forge Agent",
        "org.opencontainers.image.created": "2026-04-21T10:30:51.655Z",
        "org.opencontainers.image.description": "Telemetry Forge Agent is a stable, secure by default, OSS (Apache-licensed) downstream distribution of Fluent Bit with predictable releases and long-term supported versions for 24 months.",
        "org.opencontainers.image.licenses": "",
        "org.opencontainers.image.revision": "c8c22c66e64ca72cf7ddc8004dc31ae7050e646b",
        "org.opencontainers.image.source": "https://github.com/telemetryforge/agent",
        "org.opencontainers.image.title": "agent",
        "org.opencontainers.image.url": "https://github.com/telemetryforge/agent",
        "org.opencontainers.image.version": "v26.4.3",
        "release": "1776645941",
        "summary": "Telemetry Forge Agent is an Enterprise hardened version of Fluent Bit",
        "url": "https://telemetryforge.io",
        "vcs-ref": "0bc61a274edddc1467c2ad0ddc3139543c4da4da",
        "vcs-type": "git",
        "vendor": "Telemetry Forge at https://telemetryforge.io",
        "version": "26.4.3"
      }
    }
  },
  "distro": {
    "name": "redhat",
    "version": "9.7",
    "idLike": [
      "fedora"
    ]
  },
  "descriptor": {
    "name": "grype",
    "version": "0.116.1",
    "configuration": {
      "output": [
        "json"
      ],
      "file": "agent/security/agent/grype-26.4.3.json",
      "pretty": true,
      "distro": "",
      "add-cpes-if-none": false,
      "output-template-file": "",
      "check-for-app-update": true,
      "only-fixed": false,
      "only-notfixed": false,
      "ignore-wontfix": "",
      "platform": "",
      "search": {
        "scope": "squashed",
        "unindexed-archives": false,
        "indexed-archives": true
      },
      "ignore": [
        {
          "vulnerability": "",
          "include-aliases": false,
          "reason": "",
          "namespace": "",
          "fix-state": "",
          "package": {
            "name": "kernel-headers",
            "version": "",
            "language": "",
            "type": "rpm",
            "location": "",
            "upstream-name": "kernel"
          },
          "vex-status": "",
          "vex-justification": "",
          "match-type": "exact-indirect-match"
        },
        {
          "vulnerability": "",
          "include-aliases": false,
          "reason": "",
          "namespace": "",
          "fix-state": "",
          "package": {
            "name": "linux(-.*)?-headers-.*",
            "version": "",
            "language": "",
            "type": "deb",
            "location": "",
            "upstream-name": "linux.*"
          },
          "vex-status": "",
          "vex-justification": "",
          "match-type": "exact-indirect-match"
        },
        {
          "vulnerability": "",
          "include-aliases": false,
          "reason": "",
          "namespace": "",
          "fix-state": "",
          "package": {
            "name": "linux-libc-dev",
            "version": "",
            "language": "",
            "type": "deb",
            "location": "",
            "upstream-name": "linux"
          },
          "vex-status": "",
          "vex-justification": "",
          "match-type": "exact-indirect-match"
        },
        {
          "vulnerability": "",
          "include-aliases": false,
          "reason": "",
          "namespace": "",
          "fix-state": "",
          "package": {
            "name": "linux-kbuild-.*",
            "version": "",
            "language": "",
            "type": "deb",
            "location": "",
            "upstream-name": "linux.*"
          },
          "vex-status": "",
          "vex-justification": "",
          "match-type": "exact-indirect-match"
        }
      ],
      "exclude": [],
      "externalSources": {
        "enable": false,
        "maven": {
          "searchUpstreamBySha1": true,
          "baseUrl": "https://search.maven.org/solrsearch/select",
          "rateLimit": 300000000
        }
      },
      "match": {
        "java": {
          "using-cpes": false
        },
        "jvm": {
          "using-cpes": true
        },
        "dotnet": {
          "using-cpes": false
        },
        "golang": {
          "using-cpes": false,
          "always-use-cpe-for-stdlib": false,
          "allow-main-module-pseudo-version-comparison": false
        },
        "javascript": {
          "using-cpes": false
        },
        "python": {
          "using-cpes": false
        },
        "ruby": {
          "using-cpes": false
        },
        "rust": {
          "using-cpes": false
        },
        "hex": {
          "using-cpes": false
        },
        "stock": {
          "using-cpes": true
        },
        "dpkg": {
          "using-cpes": false,
          "missing-epoch-strategy": "zero",
          "use-cpes-for-eol": false
        },
        "rpm": {
          "using-cpes": false,
          "missing-epoch-strategy": "auto",
          "use-cpes-for-eol": false
        }
      },
      "fail-on-severity": "",
      "registry": {
        "insecure-skip-tls-verify": false,
        "insecure-use-http": false,
        "ca-cert": ""
      },
      "show-suppressed": false,
      "by-cve": false,
      "SortBy": {
        "sort-by": "risk"
      },
      "name": "",
      "default-image-pull-source": "",
      "from": null,
      "vex-documents": [],
      "vex-add": [],
      "match-upstream-kernel-headers": false,
      "fix-channel": {
        "redhat-eus": {
          "apply": "auto",
          "versions": ">= 8.0"
        },
        "ubuntu-esm": {
          "apply": "auto",
          "versions": ""
        }
      },
      "timestamp": false,
      "alerts": {
        "enable-eol-distro-warnings": true
      },
      "db": {
        "cache-dir": ".cache/grype/db",
        "update-url": "https://grype.anchore.io/databases",
        "ca-cert": "",
        "auto-update": true,
        "validate-by-hash-on-start": true,
        "validate-age": true,
        "max-allowed-built-age": 432000000000000,
        "require-update-check": false,
        "update-available-timeout": 30000000000,
        "update-download-timeout": 300000000000,
        "max-update-check-frequency": 7200000000000
      },
      "exp": {},
      "dev": {
        "db": {
          "debug": false
        }
      }
    },
    "db": {
      "status": {
        "schemaVersion": "v6.1.9",
        "from": "https://grype.anchore.io/databases/v6/vulnerability-db_v6.1.9_2026-07-29T00:35:30Z_1785308909.tar.zst?checksum=sha256%3Aea7bc3b89f29dfd4e8b10c12532caefb76f3df0bf55f604015b376cda3ed1275",
        "built": "2026-07-29T07:08:29Z",
        "path": ".cache/grype/db/6/vulnerability.db",
        "valid": true
      },
      "providers": {
        "alma": {
          "captured": "2026-07-29T00:35:30Z",
          "input": "xxh64:abb7063a7ba65fb4"
        },
        "alpine": {
          "captured": "2026-07-29T00:36:07Z",
          "input": "xxh64:8798fcdf7f914d8d"
        },
        "amazon": {
          "captured": "2026-07-29T00:36:01Z",
          "input": "xxh64:88a758ce5375f610"
        },
        "arch": {
          "captured": "2026-07-29T00:35:34Z",
          "input": "xxh64:520eab44f4a7afb9"
        },
        "bitnami": {
          "captured": "2026-07-29T00:35:48Z",
          "input": "xxh64:63ce2c93153534d1"
        },
        "chainguard": {
          "captured": "2026-07-29T00:35:39Z",
          "input": "xxh64:f21a3533886948ac"
        },
        "chainguard-libraries": {
          "captured": "2026-07-29T00:35:54Z",
          "input": "xxh64:51db172885e7d64c"
        },
        "debian": {
          "captured": "2026-07-29T00:35:40Z",
          "input": "xxh64:caafcd86e2756a35"
        },
        "echo": {
          "captured": "2026-07-29T00:35:31Z",
          "input": "xxh64:dd294ce1f17a8013"
        },
        "eol": {
          "captured": "2026-07-29T00:35:38Z",
          "input": "xxh64:847f46f09d7c4023"
        },
        "epss": {
          "captured": "2026-07-29T00:35:42Z",
          "input": "xxh64:00f000e915b52fde"
        },
        "fedora": {
          "captured": "2026-07-29T00:36:00Z",
          "input": "xxh64:ed2db138a968c477"
        },
        "github": {
          "captured": "2026-07-29T00:35:35Z",
          "input": "xxh64:4cda0a6108cedacd"
        },
        "govulndb": {
          "captured": "2026-07-29T00:35:39Z",
          "input": "xxh64:0a46e3a1eb9133d7"
        },
        "hummingbird": {
          "captured": "2026-07-29T00:37:24Z",
          "input": "xxh64:007e54f1d2374656"
        },
        "kev": {
          "captured": "2026-07-29T00:36:10Z",
          "input": "xxh64:b277e74875e2d7e7"
        },
        "mariner": {
          "captured": "2026-07-29T00:35:59Z",
          "input": "xxh64:118dde1bfa7425bc"
        },
        "minimos": {
          "captured": "2026-07-29T00:35:39Z",
          "input": "xxh64:d2790bd83cb9ab02"
        },
        "nvd": {
          "captured": "2026-07-29T00:36:37Z",
          "input": "xxh64:e2ced04648ebf499"
        },
        "oracle": {
          "captured": "2026-07-29T00:36:54Z",
          "input": "xxh64:44433375be8c9a34"
        },
        "photon": {
          "captured": "2026-07-29T00:36:43Z",
          "input": "xxh64:d76f906da09cb879"
        },
        "rhel": {
          "captured": "2026-07-29T00:36:51Z",
          "input": "xxh64:65732be4e1a2ab89"
        },
        "secureos": {
          "captured": "2026-07-29T00:35:41Z",
          "input": "xxh64:e6c0fc8dff733a0c"
        },
        "sles": {
          "captured": "2026-07-29T00:36:10Z",
          "input": "xxh64:1c10d2c3c28399e7"
        },
        "ubuntu": {
          "captured": "2026-07-29T00:41:24Z",
          "input": "xxh64:2e4b9d5c5894afac"
        },
        "wolfi": {
          "captured": "2026-07-29T00:35:51Z",
          "input": "xxh64:aa89ce46df8f030f"
        }
      }
    }
  }
}
