{
  "matches": [
    {
      "vulnerability": {
        "id": "CVE-2025-15467",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-15467",
        "namespace": "debian:distro:debian:12",
        "severity": "Critical",
        "urls": [],
        "description": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.  Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.  When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.  Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.  OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 9.8,
              "exploitabilityScore": 3.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-15467",
            "epss": 0.47621,
            "percentile": 0.98727,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-15467",
            "cwe": "CWE-787",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2025-15467",
            "cwe": "CWE-120",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.18-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.18-1~deb12u2",
              "date": "2026-01-27",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6113-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6113-1"
          }
        ],
        "risk": 44.763740000000006
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-15467",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-15467",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://github.com/openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703",
            "https://github.com/openssl/openssl/commit/5f26d4202f5b89664c5c3f3c62086276026ba9a9",
            "https://github.com/openssl/openssl/commit/6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3",
            "https://github.com/openssl/openssl/commit/ce39170276daec87f55c39dad1f629b56344429e",
            "https://github.com/openssl/openssl/commit/d0071a0799f20cc8101730145349ed4487c268dc",
            "https://openssl-library.org/news/secadv/20260127.txt",
            "http://www.openwall.com/lists/oss-security/2026/01/27/10",
            "http://www.openwall.com/lists/oss-security/2026/02/25/6",
            "https://access.redhat.com/errata/RHSA-2026:1472",
            "https://access.redhat.com/errata/RHSA-2026:1473",
            "https://access.redhat.com/errata/RHSA-2026:1496",
            "https://access.redhat.com/errata/RHSA-2026:1503",
            "https://access.redhat.com/errata/RHSA-2026:1519",
            "https://access.redhat.com/errata/RHSA-2026:1594",
            "https://access.redhat.com/errata/RHSA-2026:1733",
            "https://access.redhat.com/errata/RHSA-2026:1736",
            "https://access.redhat.com/errata/RHSA-2026:2072",
            "https://access.redhat.com/errata/RHSA-2026:2077",
            "https://access.redhat.com/errata/RHSA-2026:2485",
            "https://access.redhat.com/errata/RHSA-2026:2563",
            "https://access.redhat.com/errata/RHSA-2026:2633",
            "https://access.redhat.com/errata/RHSA-2026:2659",
            "https://access.redhat.com/errata/RHSA-2026:2671",
            "https://access.redhat.com/errata/RHSA-2026:2844",
            "https://access.redhat.com/errata/RHSA-2026:2974",
            "https://access.redhat.com/errata/RHSA-2026:2995",
            "https://access.redhat.com/errata/RHSA-2026:3228",
            "https://access.redhat.com/errata/RHSA-2026:3415",
            "https://access.redhat.com/errata/RHSA-2026:3461",
            "https://access.redhat.com/errata/RHSA-2026:3462",
            "https://access.redhat.com/errata/RHSA-2026:4419",
            "https://access.redhat.com/errata/RHSA-2026:4943",
            "https://access.redhat.com/errata/RHSA-2026:6481",
            "https://access.redhat.com/errata/RHSA-2026:7261",
            "https://access.redhat.com/security/cve/CVE-2025-15467",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2430376",
            "https://cert-portal.siemens.com/productcert/html/ssa-434797.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-734552.html",
            "https://github.com/guiimoraes/CVE-2025-15467",
            "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15467.json"
          ],
          "description": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with\nmaliciously crafted AEAD parameters can trigger a stack buffer overflow.\n\nImpact summary: A stack buffer overflow may lead to a crash, causing Denial\nof Service, or potentially remote code execution.\n\nWhen parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as\nAES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is\ncopied into a fixed-size stack buffer without verifying that its length fits\nthe destination. An attacker can supply a crafted CMS message with an\noversized IV, causing a stack-based out-of-bounds write before any\nauthentication or tag verification occurs.\n\nApplications and services that parse untrusted CMS or PKCS#7 content using\nAEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.\nBecause the overflow occurs prior to authentication, no valid key material\nis required to trigger it. While exploitability to remote code execution\ndepends on platform and toolchain mitigations, the stack-based write\nprimitive represents a severe risk.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.\n\nOpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-15467",
              "epss": 0.47621,
              "percentile": 0.98727,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-15467",
              "cwe": "CWE-787",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2025-15467",
              "cwe": "CWE-120",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-15467",
            "versionConstraint": "< 3.0.18-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.18-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-45447",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-45447",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.  Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution.  When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition.  In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution.  Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.3,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-45447",
            "epss": 0.05236,
            "percentile": 0.91668,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-45447",
            "cwe": "CWE-416",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-45447",
            "cwe": "CWE-825",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.20-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.20-1~deb12u2",
              "date": "2026-06-09",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6335-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6335-1"
          }
        ],
        "risk": 4.084079999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-45447",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-45447",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c",
            "https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8",
            "https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54",
            "https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c",
            "https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e",
            "https://openssl-library.org/news/secadv/20260609.txt",
            "https://access.redhat.com/errata/RHSA-2026:25237",
            "https://access.redhat.com/errata/RHSA-2026:25239",
            "https://access.redhat.com/errata/RHSA-2026:26275",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:34102",
            "https://access.redhat.com/errata/RHSA-2026:35869",
            "https://access.redhat.com/errata/RHSA-2026:36215",
            "https://access.redhat.com/errata/RHSA-2026:36217",
            "https://access.redhat.com/errata/RHSA-2026:39009",
            "https://access.redhat.com/errata/RHSA-2026:39012",
            "https://access.redhat.com/errata/RHSA-2026:39981",
            "https://access.redhat.com/errata/RHSA-2026:44438",
            "https://access.redhat.com/security/cve/CVE-2026-45447",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2481898",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"
          ],
          "description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.3,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-45447",
              "epss": 0.05236,
              "percentile": 0.91668,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-45447",
              "cwe": "CWE-416",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-45447",
              "cwe": "CWE-825",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-45447",
            "versionConstraint": "< 3.0.20-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.20-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2011-3389",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2011-3389",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2011-3389",
            "epss": 0.73327,
            "percentile": 0.99406,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2011-3389",
            "cwe": "CWE-326",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 3.66635
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2011-3389",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2011-3389",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/",
            "http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx",
            "http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx",
            "http://curl.haxx.se/docs/adv_20120124B.html",
            "http://downloads.asterisk.org/pub/security/AST-2016-001.html",
            "http://ekoparty.org/2011/juliano-rizzo.php",
            "http://eprint.iacr.org/2004/111",
            "http://eprint.iacr.org/2006/136",
            "http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html",
            "http://isc.sans.edu/diary/SSL+TLS+part+3+/11635",
            "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html",
            "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html",
            "http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html",
            "http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html",
            "http://lists.apple.com/archives/security-announce/2012/May/msg00001.html",
            "http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html",
            "http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html",
            "http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html",
            "http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html",
            "http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html",
            "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html",
            "http://marc.info/?l=bugtraq&m=132750579901589&w=2",
            "http://marc.info/?l=bugtraq&m=132872385320240&w=2",
            "http://marc.info/?l=bugtraq&m=133365109612558&w=2",
            "http://marc.info/?l=bugtraq&m=133728004526190&w=2",
            "http://marc.info/?l=bugtraq&m=134254866602253&w=2",
            "http://marc.info/?l=bugtraq&m=134254957702612&w=2",
            "http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue",
            "http://osvdb.org/74829",
            "http://rhn.redhat.com/errata/RHSA-2012-0508.html",
            "http://rhn.redhat.com/errata/RHSA-2013-1455.html",
            "http://secunia.com/advisories/45791",
            "http://secunia.com/advisories/47998",
            "http://secunia.com/advisories/48256",
            "http://secunia.com/advisories/48692",
            "http://secunia.com/advisories/48915",
            "http://secunia.com/advisories/48948",
            "http://secunia.com/advisories/49198",
            "http://secunia.com/advisories/55322",
            "http://secunia.com/advisories/55350",
            "http://secunia.com/advisories/55351",
            "http://security.gentoo.org/glsa/glsa-201203-02.xml",
            "http://security.gentoo.org/glsa/glsa-201406-32.xml",
            "http://support.apple.com/kb/HT4999",
            "http://support.apple.com/kb/HT5001",
            "http://support.apple.com/kb/HT5130",
            "http://support.apple.com/kb/HT5281",
            "http://support.apple.com/kb/HT5501",
            "http://support.apple.com/kb/HT6150",
            "http://technet.microsoft.com/security/advisory/2588513",
            "http://vnhacker.blogspot.com/2011/09/beast.html",
            "http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf",
            "http://www.debian.org/security/2012/dsa-2398",
            "http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html",
            "http://www.ibm.com/developerworks/java/jdk/alerts/",
            "http://www.imperialviolet.org/2011/09/23/chromeandbeast.html",
            "http://www.insecure.cl/Beast-SSL.rar",
            "http://www.kb.cert.org/vuls/id/864643",
            "http://www.mandriva.com/security/advisories?name=MDVSA-2012:058",
            "http://www.opera.com/docs/changelogs/mac/1151/",
            "http://www.opera.com/docs/changelogs/mac/1160/",
            "http://www.opera.com/docs/changelogs/unix/1151/",
            "http://www.opera.com/docs/changelogs/unix/1160/",
            "http://www.opera.com/docs/changelogs/windows/1151/",
            "http://www.opera.com/docs/changelogs/windows/1160/",
            "http://www.opera.com/support/kb/view/1004/",
            "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html",
            "http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html",
            "http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html",
            "http://www.redhat.com/support/errata/RHSA-2011-1384.html",
            "http://www.redhat.com/support/errata/RHSA-2012-0006.html",
            "http://www.securityfocus.com/bid/49388",
            "http://www.securityfocus.com/bid/49778",
            "http://www.securitytracker.com/id/1029190",
            "http://www.securitytracker.com/id?1025997",
            "http://www.securitytracker.com/id?1026103",
            "http://www.securitytracker.com/id?1026704",
            "http://www.ubuntu.com/usn/USN-1263-1",
            "http://www.us-cert.gov/cas/techalerts/TA12-010A.html",
            "https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail",
            "https://bugzilla.novell.com/show_bug.cgi?id=719047",
            "https://bugzilla.redhat.com/show_bug.cgi?id=737506",
            "https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf",
            "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006",
            "https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862",
            "https://hermes.opensuse.org/messages/13154861",
            "https://hermes.opensuse.org/messages/13155432",
            "https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02",
            "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"
          ],
          "description": "The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 8.6,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2011-3389",
              "epss": 0.73327,
              "percentile": 0.99406,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2011-3389",
              "cwe": "CWE-326",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2011-3389",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-55200",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-55200",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L",
            "metrics": {
              "baseScore": 8.3,
              "exploitabilityScore": 2.9,
              "impactScore": 5.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-55200",
            "epss": 0.02027,
            "percentile": 0.79016,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-55200",
            "cwe": "CWE-680",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 1.6013300000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-55200",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-55200",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8",
            "https://github.com/libssh2/libssh2/pull/2052",
            "https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c",
            "https://web.archive.org/web/20260623211210/https://github.com/bikini/exploitarium/tree/main/libssh2-cve-2026-55200-poc"
          ],
          "description": "libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L",
              "metrics": {
                "baseScore": 8.3,
                "exploitabilityScore": 2.9,
                "impactScore": 5.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 9.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.3,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-55200",
              "epss": 0.02027,
              "percentile": 0.79016,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-55200",
              "cwe": "CWE-680",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libssh2",
              "version": "1.10.0-3"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-55200",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8905b74027385650",
        "name": "libssh2-1",
        "version": "1.10.0-3+b1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssh2-1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssh2-1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12&upstream=libssh2%401.10.0-3",
        "upstreams": [
          {
            "name": "libssh2",
            "version": "1.10.0-3"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-2953",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2023-2953",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2023-2953",
            "epss": 0.01947,
            "percentile": 0.78103,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2023-2953",
            "cwe": "CWE-476",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2023-2953",
            "cwe": "CWE-476",
            "source": "nvd@nist.gov",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2023-2953",
            "cwe": "CWE-476",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 1.46025
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-2953",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-2953",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "http://seclists.org/fulldisclosure/2023/Jul/47",
            "http://seclists.org/fulldisclosure/2023/Jul/48",
            "http://seclists.org/fulldisclosure/2023/Jul/52",
            "https://access.redhat.com/security/cve/CVE-2023-2953",
            "https://bugs.openldap.org/show_bug.cgi?id=9904",
            "https://security.netapp.com/advisory/ntap-20230703-0005/",
            "https://support.apple.com/kb/HT213843",
            "https://support.apple.com/kb/HT213844",
            "https://support.apple.com/kb/HT213845"
          ],
          "description": "A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-2953",
              "epss": 0.01947,
              "percentile": 0.78103,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2023-2953",
              "cwe": "CWE-476",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2023-2953",
              "cwe": "CWE-476",
              "source": "nvd@nist.gov",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2023-2953",
              "cwe": "CWE-476",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openldap",
              "version": "2.5.13+dfsg-5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-2953",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "919a44d8cbaa32e2",
        "name": "libldap-2.5-0",
        "version": "2.5.13+dfsg-5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12&upstream=openldap",
        "upstreams": [
          {
            "name": "openldap"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-9230",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-9230",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code.  Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy.  The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-9230",
            "epss": 0.01744,
            "percentile": 0.75459,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-9230",
            "cwe": "CWE-125",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2025-9230",
            "cwe": "CWE-787",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.17-1~deb12u3"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.17-1~deb12u3",
              "date": "2025-10-01",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6015-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6015-1"
          }
        ],
        "risk": 1.308
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-9230",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-9230",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/5965ea5dd6960f36d8b7f74f8eac67a8eb8f2b45",
            "https://github.com/openssl/openssl/commit/9e91358f365dee6c446dcdcdb01c04d2743fd280",
            "https://github.com/openssl/openssl/commit/a79c4ce559c6a3a8fd4109e9f33c1185d5bf2def",
            "https://github.com/openssl/openssl/commit/b5282d677551afda7d20e9c00e09561b547b2dfd",
            "https://github.com/openssl/openssl/commit/bae259a211ada6315dc50900686daaaaaa55f482",
            "https://github.openssl.org/openssl/extended-releases/commit/c2b96348bfa662f25f4fabf81958ae822063dae3",
            "https://github.openssl.org/openssl/extended-releases/commit/dfbaf161d8dafc1132dd88cd48ad990ed9b4c8ba",
            "https://openssl-library.org/news/secadv/20250930.txt",
            "http://www.openwall.com/lists/oss-security/2025/09/30/5",
            "https://lists.debian.org/debian-lts-announce/2025/10/msg00001.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-089022.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-485750.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
          ],
          "description": "Issue summary: An application trying to decrypt CMS messages encrypted using\npassword based encryption can trigger an out-of-bounds read and write.\n\nImpact summary: This out-of-bounds read may trigger a crash which leads to\nDenial of Service for an application. The out-of-bounds write can cause\na memory corruption which can have various consequences including\na Denial of Service or Execution of attacker-supplied code.\n\nAlthough the consequences of a successful exploit of this vulnerability\ncould be severe, the probability that the attacker would be able to\nperform it is low. Besides, password based (PWRI) encryption support in CMS\nmessages is very rarely used. For that reason the issue was assessed as\nModerate severity according to our Security Policy.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-9230",
              "epss": 0.01744,
              "percentile": 0.75459,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-9230",
              "cwe": "CWE-125",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2025-9230",
              "cwe": "CWE-787",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-9230",
            "versionConstraint": "< 3.0.17-1~deb12u3 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.17-1~deb12u3"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-9232",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-9232",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address.  Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application.  The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker.  In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity.  The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.  The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-9232",
            "epss": 0.02251,
            "percentile": 0.81098,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-9232",
            "cwe": "CWE-125",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.17-1~deb12u3"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.17-1~deb12u3",
              "date": "2025-10-01",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6015-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6015-1"
          }
        ],
        "risk": 1.226795
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-9232",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-9232",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35",
            "https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b",
            "https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3",
            "https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf",
            "https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0",
            "https://openssl-library.org/news/secadv/20250930.txt",
            "http://www.openwall.com/lists/oss-security/2025/09/30/5",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-089022.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-485750.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
          ],
          "description": "Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-9232",
              "epss": 0.02251,
              "percentile": 0.81098,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-9232",
              "cwe": "CWE-125",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-9232",
            "versionConstraint": "< 3.0.17-1~deb12u3 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.17-1~deb12u3"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42009",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-42009",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42009",
            "epss": 0.01335,
            "percentile": 0.68258,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42009",
            "cwe": "CWE-475",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-42009",
            "cwe": "CWE-475",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 1.00125
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42009",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42009",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:29794",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:34372",
            "https://access.redhat.com/errata/RHSA-2026:34764",
            "https://access.redhat.com/errata/RHSA-2026:34788",
            "https://access.redhat.com/errata/RHSA-2026:36004",
            "https://access.redhat.com/errata/RHSA-2026:36005",
            "https://access.redhat.com/errata/RHSA-2026:36006",
            "https://access.redhat.com/errata/RHSA-2026:40762",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/security/cve/CVE-2026-42009",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467279",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json"
          ],
          "description": "A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42009",
              "epss": 0.01335,
              "percentile": 0.68258,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42009",
              "cwe": "CWE-475",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-42009",
              "cwe": "CWE-475",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42009",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42010",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-42010",
        "namespace": "debian:distro:debian:12",
        "severity": "Critical",
        "urls": [],
        "description": "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 9.8,
              "exploitabilityScore": 3.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42010",
            "epss": 0.0105,
            "percentile": 0.60781,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42010",
            "cwe": "CWE-170",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-42010",
            "cwe": "CWE-626",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-42010",
            "cwe": "CWE-170",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 0.9870000000000002
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42010",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42010",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:34764",
            "https://access.redhat.com/errata/RHSA-2026:34788",
            "https://access.redhat.com/errata/RHSA-2026:34790",
            "https://access.redhat.com/errata/RHSA-2026:36004",
            "https://access.redhat.com/errata/RHSA-2026:36005",
            "https://access.redhat.com/errata/RHSA-2026:36006",
            "https://access.redhat.com/errata/RHSA-2026:40762",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/security/cve/CVE-2026-42010",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467289",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-4",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42010.json"
          ],
          "description": "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 2.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 2.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42010",
              "epss": 0.0105,
              "percentile": 0.60781,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42010",
              "cwe": "CWE-170",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-42010",
              "cwe": "CWE-626",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-42010",
              "cwe": "CWE-170",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42010",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-2005",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-2005",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.8,
              "exploitabilityScore": 2.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-2005",
            "epss": 0.01208,
            "percentile": 0.65219,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-2005",
            "cwe": "CWE-122",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-2005",
            "cwe": "CWE-120",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.16-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.16-0+deb12u1",
              "date": "2026-02-12",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6132-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6132-1"
          }
        ],
        "risk": 0.9845200000000002
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-2005",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-2005",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-2005/",
            "https://access.redhat.com/errata/RHSA-2026:19009",
            "https://access.redhat.com/errata/RHSA-2026:19010",
            "https://access.redhat.com/errata/RHSA-2026:3730",
            "https://access.redhat.com/errata/RHSA-2026:3887",
            "https://access.redhat.com/errata/RHSA-2026:3896",
            "https://access.redhat.com/errata/RHSA-2026:4024",
            "https://access.redhat.com/errata/RHSA-2026:4059",
            "https://access.redhat.com/errata/RHSA-2026:4063",
            "https://access.redhat.com/errata/RHSA-2026:4064",
            "https://access.redhat.com/errata/RHSA-2026:4074",
            "https://access.redhat.com/errata/RHSA-2026:4075",
            "https://access.redhat.com/errata/RHSA-2026:4110",
            "https://access.redhat.com/errata/RHSA-2026:4254",
            "https://access.redhat.com/errata/RHSA-2026:4441",
            "https://access.redhat.com/errata/RHSA-2026:4475",
            "https://access.redhat.com/errata/RHSA-2026:4504",
            "https://access.redhat.com/errata/RHSA-2026:4505",
            "https://access.redhat.com/errata/RHSA-2026:4506",
            "https://access.redhat.com/errata/RHSA-2026:4509",
            "https://access.redhat.com/errata/RHSA-2026:4515",
            "https://access.redhat.com/errata/RHSA-2026:4516",
            "https://access.redhat.com/errata/RHSA-2026:4518",
            "https://access.redhat.com/errata/RHSA-2026:4524",
            "https://access.redhat.com/errata/RHSA-2026:4528",
            "https://access.redhat.com/errata/RHSA-2026:4544",
            "https://access.redhat.com/errata/RHSA-2026:4546",
            "https://access.redhat.com/errata/RHSA-2026:4547",
            "https://access.redhat.com/errata/RHSA-2026:4548",
            "https://access.redhat.com/errata/RHSA-2026:4943",
            "https://access.redhat.com/errata/RHSA-2026:8756",
            "https://access.redhat.com/security/cve/CVE-2026-2005",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2439326",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2005.json"
          ],
          "description": "Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-2005",
              "epss": 0.01208,
              "percentile": 0.65219,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-2005",
              "cwe": "CWE-122",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-2005",
              "cwe": "CWE-120",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-2005",
            "versionConstraint": "< 15.16-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.16-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-33846",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-33846",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-33846",
            "epss": 0.01263,
            "percentile": 0.66672,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-33846",
            "cwe": "CWE-130",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-33846",
            "cwe": "CWE-130",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 0.94725
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-33846",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-33846",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:34372",
            "https://access.redhat.com/errata/RHSA-2026:36004",
            "https://access.redhat.com/errata/RHSA-2026:36005",
            "https://access.redhat.com/errata/RHSA-2026:36006",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/security/cve/CVE-2026-33846",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2450625",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33846.json"
          ],
          "description": "A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-33846",
              "epss": 0.01263,
              "percentile": 0.66672,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-33846",
              "cwe": "CWE-130",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-33846",
              "cwe": "CWE-130",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-33846",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-31790",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-31790",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-31790",
            "epss": 0.01202,
            "percentile": 0.65053,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-31790",
            "cwe": "CWE-754",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.19-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.19-1~deb12u2",
              "date": "2026-04-07",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6201-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6201-1"
          }
        ],
        "risk": 0.9014999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-31790",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-31790",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac",
            "https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482",
            "https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406",
            "https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790",
            "https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-31790",
              "epss": 0.01202,
              "percentile": 0.65053,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-31790",
              "cwe": "CWE-754",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-31790",
            "versionConstraint": "< 3.0.19-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.19-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-2006",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-2006",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun.  That suffices to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.8,
              "exploitabilityScore": 2.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-2006",
            "epss": 0.01079,
            "percentile": 0.6164,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-2006",
            "cwe": "CWE-129",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-2006",
            "cwe": "CWE-1285",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.16-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.16-0+deb12u1",
              "date": "2026-02-12",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6132-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6132-1"
          }
        ],
        "risk": 0.8793850000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-2006",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-2006",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-2006/",
            "https://access.redhat.com/errata/RHSA-2026:19009",
            "https://access.redhat.com/errata/RHSA-2026:19010",
            "https://access.redhat.com/errata/RHSA-2026:3730",
            "https://access.redhat.com/errata/RHSA-2026:3887",
            "https://access.redhat.com/errata/RHSA-2026:3896",
            "https://access.redhat.com/errata/RHSA-2026:4024",
            "https://access.redhat.com/errata/RHSA-2026:4059",
            "https://access.redhat.com/errata/RHSA-2026:4063",
            "https://access.redhat.com/errata/RHSA-2026:4064",
            "https://access.redhat.com/errata/RHSA-2026:4074",
            "https://access.redhat.com/errata/RHSA-2026:4075",
            "https://access.redhat.com/errata/RHSA-2026:4110",
            "https://access.redhat.com/errata/RHSA-2026:4254",
            "https://access.redhat.com/errata/RHSA-2026:4441",
            "https://access.redhat.com/errata/RHSA-2026:4475",
            "https://access.redhat.com/errata/RHSA-2026:4504",
            "https://access.redhat.com/errata/RHSA-2026:4505",
            "https://access.redhat.com/errata/RHSA-2026:4506",
            "https://access.redhat.com/errata/RHSA-2026:4509",
            "https://access.redhat.com/errata/RHSA-2026:4515",
            "https://access.redhat.com/errata/RHSA-2026:4516",
            "https://access.redhat.com/errata/RHSA-2026:4518",
            "https://access.redhat.com/errata/RHSA-2026:4524",
            "https://access.redhat.com/errata/RHSA-2026:4528",
            "https://access.redhat.com/errata/RHSA-2026:4544",
            "https://access.redhat.com/errata/RHSA-2026:4546",
            "https://access.redhat.com/errata/RHSA-2026:4547",
            "https://access.redhat.com/errata/RHSA-2026:4548",
            "https://access.redhat.com/errata/RHSA-2026:4943",
            "https://access.redhat.com/errata/RHSA-2026:8756",
            "https://access.redhat.com/security/cve/CVE-2026-2006",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2439324",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2006.json"
          ],
          "description": "Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun.  That suffices to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-2006",
              "epss": 0.01079,
              "percentile": 0.6164,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-2006",
              "cwe": "CWE-129",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-2006",
              "cwe": "CWE-1285",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-2006",
            "versionConstraint": "< 15.16-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.16-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-13151",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-13151",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-13151",
            "epss": 0.01109,
            "percentile": 0.62532,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-13151",
            "cwe": "CWE-787",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.8317499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-13151",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-13151",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://gitlab.com/gnutls/libtasn1",
            "https://gitlab.com/gnutls/libtasn1/-/merge_requests/121",
            "http://www.openwall.com/lists/oss-security/2026/01/08/5",
            "https://www.kb.cert.org/vuls/id/271649"
          ],
          "description": "Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-13151",
              "epss": 0.01109,
              "percentile": 0.62532,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-13151",
              "cwe": "CWE-787",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libtasn1-6",
              "version": "4.19.0-2+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-13151",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "48b70e4d102cdd4b",
        "name": "libtasn1-6",
        "version": "4.19.0-2+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libtasn1-6",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libtasn1-6",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libtasn1-6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libtasn1-6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libtasn1_6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libtasn1_6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libtasn1:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libtasn1:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libtasn1-6@4.19.0-2%2Bdeb12u1?arch=amd64&distro=debian-12",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6473",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6473",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds.  This may execute arbitrary code as the operating system user running the database.  In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.8,
              "exploitabilityScore": 2.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6473",
            "epss": 0.01006,
            "percentile": 0.59452,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6473",
            "cwe": "CWE-190",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-6473",
            "cwe": "CWE-190",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.18-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.18-0+deb12u1",
              "date": "2026-05-14",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6269-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6269-1"
          }
        ],
        "risk": 0.81989
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6473",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6473",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-6473/",
            "https://access.redhat.com/errata/RHSA-2026:22878",
            "https://access.redhat.com/errata/RHSA-2026:26181",
            "https://access.redhat.com/errata/RHSA-2026:26203",
            "https://access.redhat.com/errata/RHSA-2026:26204",
            "https://access.redhat.com/errata/RHSA-2026:26524",
            "https://access.redhat.com/errata/RHSA-2026:26525",
            "https://access.redhat.com/errata/RHSA-2026:26561",
            "https://access.redhat.com/errata/RHSA-2026:27718",
            "https://access.redhat.com/errata/RHSA-2026:27738",
            "https://access.redhat.com/errata/RHSA-2026:27741",
            "https://access.redhat.com/errata/RHSA-2026:27742",
            "https://access.redhat.com/errata/RHSA-2026:27743",
            "https://access.redhat.com/errata/RHSA-2026:28037",
            "https://access.redhat.com/errata/RHSA-2026:28143",
            "https://access.redhat.com/errata/RHSA-2026:28208",
            "https://access.redhat.com/errata/RHSA-2026:28999",
            "https://access.redhat.com/errata/RHSA-2026:29212",
            "https://access.redhat.com/errata/RHSA-2026:29815",
            "https://access.redhat.com/errata/RHSA-2026:29904",
            "https://access.redhat.com/errata/RHSA-2026:29953",
            "https://access.redhat.com/errata/RHSA-2026:32983",
            "https://access.redhat.com/errata/RHSA-2026:32994",
            "https://access.redhat.com/errata/RHSA-2026:33441",
            "https://access.redhat.com/errata/RHSA-2026:33497",
            "https://access.redhat.com/errata/RHSA-2026:34043",
            "https://access.redhat.com/errata/RHSA-2026:34362",
            "https://access.redhat.com/errata/RHSA-2026:34363",
            "https://access.redhat.com/errata/RHSA-2026:35880",
            "https://access.redhat.com/errata/RHSA-2026:42555",
            "https://access.redhat.com/errata/RHSA-2026:44420",
            "https://access.redhat.com/errata/RHSA-2026:44481",
            "https://access.redhat.com/errata/RHSA-2026:44568",
            "https://access.redhat.com/security/cve/CVE-2026-6473",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2477448",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6473.json"
          ],
          "description": "Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds.  This may execute arbitrary code as the operating system user running the database.  In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6473",
              "epss": 0.01006,
              "percentile": 0.59452,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6473",
              "cwe": "CWE-190",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-6473",
              "cwe": "CWE-190",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6473",
            "versionConstraint": "< 15.18-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.18-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-28388",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-28388",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-28388",
            "epss": 0.01059,
            "percentile": 0.61046,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-28388",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.19-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.19-1~deb12u2",
              "date": "2026-04-07",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6201-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6201-1"
          }
        ],
        "risk": 0.79425
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-28388",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-28388",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e",
            "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139",
            "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3",
            "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8",
            "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-28388",
              "epss": 0.01059,
              "percentile": 0.61046,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-28388",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-28388",
            "versionConstraint": "< 3.0.19-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.19-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-28389",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-28389",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-28389",
            "epss": 0.01027,
            "percentile": 0.60095,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-28389",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.19-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.19-1~deb12u2",
              "date": "2026-04-07",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6201-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6201-1"
          }
        ],
        "risk": 0.7702499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-28389",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-28389",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5",
            "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616",
            "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f",
            "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a",
            "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-28389",
              "epss": 0.01027,
              "percentile": 0.60095,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-28389",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-28389",
            "versionConstraint": "< 3.0.19-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.19-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-28390",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-28390",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-28390",
            "epss": 0.01027,
            "percentile": 0.60095,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-28390",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.19-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.19-1~deb12u2",
              "date": "2026-04-07",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6201-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6201-1"
          }
        ],
        "risk": 0.7702499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-28390",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-28390",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc",
            "https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6",
            "https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4",
            "https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788",
            "https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-28390",
              "epss": 0.01027,
              "percentile": 0.60095,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-28390",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-28390",
            "versionConstraint": "< 3.0.19-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.19-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34180",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-34180",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.  Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer.  More typically such ASN.1 elements would instead be truncated.  An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the worst case the truncated length is treated as a request to scan the binary content for a terminating zero byte, possibly causing OpenSSL to read either less than or beyond the end of the allocated buffer.  Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or any other d2i_* decoding function are affected. OpenSSL's own command-line tools are not vulnerable, as data read through the BIO layer is checked before it reaches the affected code. The issue only affects 64-bit Unix and Unix-like platforms; 32-bit platforms and 64-bit Windows are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34180",
            "epss": 0.01025,
            "percentile": 0.60056,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34180",
            "cwe": "CWE-125",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.20-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.20-1~deb12u2",
              "date": "2026-06-09",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6335-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6335-1"
          }
        ],
        "risk": 0.76875
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34180",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34180",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d",
            "https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83",
            "https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff",
            "https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43",
            "https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34180",
              "epss": 0.01025,
              "percentile": 0.60056,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34180",
              "cwe": "CWE-125",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34180",
            "versionConstraint": "< 3.0.20-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.20-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-33845",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-33845",
        "namespace": "debian:distro:debian:12",
        "severity": "Critical",
        "urls": [],
        "description": "A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "metrics": {
              "baseScore": 9.1,
              "exploitabilityScore": 3.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-33845",
            "epss": 0.00805,
            "percentile": 0.53074,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-33845",
            "cwe": "CWE-191",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-33845",
            "cwe": "CWE-191",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 0.728525
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-33845",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-33845",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:34372",
            "https://access.redhat.com/errata/RHSA-2026:36004",
            "https://access.redhat.com/errata/RHSA-2026:36005",
            "https://access.redhat.com/errata/RHSA-2026:36006",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/security/cve/CVE-2026-33845",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2450624",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33845.json"
          ],
          "description": "A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-33845",
              "epss": 0.00805,
              "percentile": 0.53074,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-33845",
              "cwe": "CWE-191",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-33845",
              "cwe": "CWE-191",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-33845",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-12970",
        "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-12970",
        "namespace": "nvd:cpe",
        "severity": "High",
        "urls": [
          "https://fluentbit.io/blog/2025/10/28/security-vulnerabilities-addressed-in-fluent-bit-v4.1-and-backported-to-v4.0/",
          "https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover"
        ],
        "description": "The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating length. An attacker who can create containers or control container names, can supply a long name that overflows the buffer, leading to process crash or arbitrary code execution.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.8,
              "exploitabilityScore": 2.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-12970",
            "epss": 0.00881,
            "percentile": 0.55458,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-12970",
            "cwe": "CWE-120",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": ""
        },
        "advisories": [],
        "risk": 0.7180150000000001
      },
      "relatedVulnerabilities": [],
      "matchDetails": [
        {
          "type": "cpe-match",
          "matcher": "stock-matcher",
          "searchedBy": {
            "namespace": "nvd:cpe",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
            ],
            "package": {
              "name": "fluent-bit",
              "version": "4.1.0"
            }
          },
          "found": {
            "vulnerabilityID": "CVE-2025-12970",
            "versionConstraint": "= 4.1.0 (unknown)",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*"
            ]
          }
        }
      ],
      "artifact": {
        "id": "c9f8017f4b3fb0ab",
        "name": "fluent-bit",
        "version": "4.1.0",
        "type": "binary",
        "locations": [
          {
            "path": "/fluent-bit/bin/fluent-bit",
            "layerID": "sha256:0f3590c76e91ee02acf305bdcff2f981bc9f783070524382028f071e8da36d86",
            "accessPath": "/fluent-bit/bin/fluent-bit",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:github/fluent/fluent-bit@4.1.0",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-55199",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-55199",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-55199",
            "epss": 0.00918,
            "percentile": 0.56615,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-55199",
            "cwe": "CWE-835",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.6885
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-55199",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-55199",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/libssh2/libssh2/commit/17626857d20b3c9a1addfa45979dadcee1cd84a4",
            "https://github.com/libssh2/libssh2/pull/1864",
            "https://www.vulncheck.com/advisories/libssh2-pre-authentication-dos-via-ssh-msg-ext-info-handler"
          ],
          "description": "libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 8.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-55199",
              "epss": 0.00918,
              "percentile": 0.56615,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-55199",
              "cwe": "CWE-835",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libssh2",
              "version": "1.10.0-3"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-55199",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8905b74027385650",
        "name": "libssh2-1",
        "version": "1.10.0-3+b1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssh2-1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssh2-1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12&upstream=libssh2%401.10.0-3",
        "upstreams": [
          {
            "name": "libssh2",
            "version": "1.10.0-3"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-12977",
        "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-12977",
        "namespace": "nvd:cpe",
        "severity": "Critical",
        "urls": [
          "https://fluentbit.io/blog/2025/10/28/security-vulnerabilities-addressed-in-fluent-bit-v4.1-and-backported-to-v4.0/",
          "https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover"
        ],
        "description": "Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid tags. Because tags influence routing and some outputs derive filenames or contents from tags, this can allow newline injection, path traversal, forged record injection, or log misrouting, impacting data integrity and log routing.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 9.1,
              "exploitabilityScore": 3.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-12977",
            "epss": 0.00713,
            "percentile": 0.49902,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-12977",
            "cwe": "CWE-1287",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": ""
        },
        "advisories": [],
        "risk": 0.645265
      },
      "relatedVulnerabilities": [],
      "matchDetails": [
        {
          "type": "cpe-match",
          "matcher": "stock-matcher",
          "searchedBy": {
            "namespace": "nvd:cpe",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
            ],
            "package": {
              "name": "fluent-bit",
              "version": "4.1.0"
            }
          },
          "found": {
            "vulnerabilityID": "CVE-2025-12977",
            "versionConstraint": "= 4.1.0 (unknown)",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*"
            ]
          }
        }
      ],
      "artifact": {
        "id": "c9f8017f4b3fb0ab",
        "name": "fluent-bit",
        "version": "4.1.0",
        "type": "binary",
        "locations": [
          {
            "path": "/fluent-bit/bin/fluent-bit",
            "layerID": "sha256:0f3590c76e91ee02acf305bdcff2f981bc9f783070524382028f071e8da36d86",
            "accessPath": "/fluent-bit/bin/fluent-bit",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:github/fluent/fluent-bit@4.1.0",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-2004",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-2004",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.8,
              "exploitabilityScore": 2.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-2004",
            "epss": 0.00785,
            "percentile": 0.52379,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-2004",
            "cwe": "CWE-1287",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-2004",
            "cwe": "CWE-1287",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.16-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.16-0+deb12u1",
              "date": "2026-02-12",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6132-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6132-1"
          }
        ],
        "risk": 0.639775
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-2004",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-2004",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-2004/",
            "https://access.redhat.com/errata/RHSA-2026:19009",
            "https://access.redhat.com/errata/RHSA-2026:19010",
            "https://access.redhat.com/errata/RHSA-2026:3730",
            "https://access.redhat.com/errata/RHSA-2026:3887",
            "https://access.redhat.com/errata/RHSA-2026:3896",
            "https://access.redhat.com/errata/RHSA-2026:4024",
            "https://access.redhat.com/errata/RHSA-2026:4059",
            "https://access.redhat.com/errata/RHSA-2026:4063",
            "https://access.redhat.com/errata/RHSA-2026:4064",
            "https://access.redhat.com/errata/RHSA-2026:4074",
            "https://access.redhat.com/errata/RHSA-2026:4075",
            "https://access.redhat.com/errata/RHSA-2026:4110",
            "https://access.redhat.com/errata/RHSA-2026:4254",
            "https://access.redhat.com/errata/RHSA-2026:4441",
            "https://access.redhat.com/errata/RHSA-2026:4475",
            "https://access.redhat.com/errata/RHSA-2026:4504",
            "https://access.redhat.com/errata/RHSA-2026:4505",
            "https://access.redhat.com/errata/RHSA-2026:4506",
            "https://access.redhat.com/errata/RHSA-2026:4509",
            "https://access.redhat.com/errata/RHSA-2026:4515",
            "https://access.redhat.com/errata/RHSA-2026:4516",
            "https://access.redhat.com/errata/RHSA-2026:4518",
            "https://access.redhat.com/errata/RHSA-2026:4524",
            "https://access.redhat.com/errata/RHSA-2026:4528",
            "https://access.redhat.com/errata/RHSA-2026:4544",
            "https://access.redhat.com/errata/RHSA-2026:4546",
            "https://access.redhat.com/errata/RHSA-2026:4547",
            "https://access.redhat.com/errata/RHSA-2026:4548",
            "https://access.redhat.com/errata/RHSA-2026:4943",
            "https://access.redhat.com/errata/RHSA-2026:8756",
            "https://access.redhat.com/security/cve/CVE-2026-2004",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2439325",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2004.json"
          ],
          "description": "Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-2004",
              "epss": 0.00785,
              "percentile": 0.52379,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-2004",
              "cwe": "CWE-1287",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-2004",
              "cwe": "CWE-1287",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-2004",
            "versionConstraint": "< 15.16-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.16-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-69421",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-69421",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.  Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files.  The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure.  Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-69421",
            "epss": 0.00844,
            "percentile": 0.54245,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-69421",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.18-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.18-1~deb12u2",
              "date": "2026-01-27",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6113-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6113-1"
          }
        ],
        "risk": 0.633
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-69421",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-69421",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/3524a29271f8191b8fd8a5257eb05173982a097b",
            "https://github.com/openssl/openssl/commit/36ecb4960872a4ce04bf6f1e1f4e78d75ec0c0c7",
            "https://github.com/openssl/openssl/commit/4bbc8d41a72c842ce4077a8a3eccd1109aaf74bd",
            "https://github.com/openssl/openssl/commit/643986985cd1c21221f941129d76fe0c2785aeb3",
            "https://github.com/openssl/openssl/commit/a2dbc539f0f9cc63832709fa5aa33ad9495eb19c",
            "https://openssl-library.org/news/secadv/20260127.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer\ndereference in the PKCS12_item_decrypt_d2i_ex() function.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to\nDenial of Service for an application processing PKCS#12 files.\n\nThe PKCS12_item_decrypt_d2i_ex() function does not check whether the oct\nparameter is NULL before dereferencing it. When called from\nPKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can\nbe NULL, causing a crash. The vulnerability is limited to Denial of Service\nand cannot be escalated to achieve code execution or memory disclosure.\n\nExploiting this issue requires an attacker to provide a malformed PKCS#12 file\nto an application that processes it. For that reason the issue was assessed as\nLow severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-69421",
              "epss": 0.00844,
              "percentile": 0.54245,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-69421",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-69421",
            "versionConstraint": "< 3.0.18-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.18-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-28387",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-28387",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.3,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-28387",
            "epss": 0.00803,
            "percentile": 0.52989,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-28387",
            "cwe": "CWE-416",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.19-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.19-1~deb12u2",
              "date": "2026-04-07",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6201-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6201-1"
          }
        ],
        "risk": 0.62634
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-28387",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-28387",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b",
            "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe",
            "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3",
            "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7",
            "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.3,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.3,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-28387",
              "epss": 0.00803,
              "percentile": 0.52989,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-28387",
              "cwe": "CWE-416",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-28387",
            "versionConstraint": "< 3.0.19-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.19-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-15661",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-15661",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.3,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-15661",
            "epss": 0.0103,
            "percentile": 0.60187,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-15661",
            "cwe": "CWE-125",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.5922499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-15661",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-15661",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d",
            "https://github.com/libssh2/libssh2/pull/1705",
            "https://github.com/libssh2/libssh2/pull/1717",
            "https://www.vulncheck.com/advisories/libssh2-heap-buffer-over-read-via-sftp-symlink-in-sftp-c"
          ],
          "description": "libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.3,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 8.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.3,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-15661",
              "epss": 0.0103,
              "percentile": 0.60187,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-15661",
              "cwe": "CWE-125",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libssh2",
              "version": "1.10.0-3"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-15661",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8905b74027385650",
        "name": "libssh2-1",
        "version": "1.10.0-3+b1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssh2-1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssh2-1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12&upstream=libssh2%401.10.0-3",
        "upstreams": [
          {
            "name": "libssh2",
            "version": "1.10.0-3"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-27135",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-27135",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-27135",
            "epss": 0.00775,
            "percentile": 0.52067,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-27135",
            "cwe": "CWE-617",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-27135",
            "cwe": "CWE-617",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1.52.0-1+deb12u3"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1.52.0-1+deb12u3",
              "date": "2026-05-14",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6266-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6266-1"
          }
        ],
        "risk": 0.58125
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-27135",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-27135",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1",
            "https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6",
            "http://www.openwall.com/lists/oss-security/2026/03/20/3",
            "https://lists.debian.org/debian-lts-announce/2026/05/msg00025.html",
            "https://access.redhat.com/errata/RHSA-2026:10065",
            "https://access.redhat.com/errata/RHSA-2026:11768",
            "https://access.redhat.com/errata/RHSA-2026:13812",
            "https://access.redhat.com/errata/RHSA-2026:14773",
            "https://access.redhat.com/errata/RHSA-2026:14937",
            "https://access.redhat.com/errata/RHSA-2026:15087",
            "https://access.redhat.com/errata/RHSA-2026:16008",
            "https://access.redhat.com/errata/RHSA-2026:16009",
            "https://access.redhat.com/errata/RHSA-2026:16030",
            "https://access.redhat.com/errata/RHSA-2026:16174",
            "https://access.redhat.com/errata/RHSA-2026:17596",
            "https://access.redhat.com/errata/RHSA-2026:19724",
            "https://access.redhat.com/errata/RHSA-2026:19725",
            "https://access.redhat.com/errata/RHSA-2026:20040",
            "https://access.redhat.com/errata/RHSA-2026:20087",
            "https://access.redhat.com/errata/RHSA-2026:21656",
            "https://access.redhat.com/errata/RHSA-2026:21690",
            "https://access.redhat.com/errata/RHSA-2026:21695",
            "https://access.redhat.com/errata/RHSA-2026:25096",
            "https://access.redhat.com/errata/RHSA-2026:27200",
            "https://access.redhat.com/errata/RHSA-2026:27201",
            "https://access.redhat.com/errata/RHSA-2026:6190",
            "https://access.redhat.com/errata/RHSA-2026:7080",
            "https://access.redhat.com/errata/RHSA-2026:7123",
            "https://access.redhat.com/errata/RHSA-2026:7302",
            "https://access.redhat.com/errata/RHSA-2026:7310",
            "https://access.redhat.com/errata/RHSA-2026:7350",
            "https://access.redhat.com/errata/RHSA-2026:7666",
            "https://access.redhat.com/errata/RHSA-2026:7667",
            "https://access.redhat.com/errata/RHSA-2026:7668",
            "https://access.redhat.com/errata/RHSA-2026:7670",
            "https://access.redhat.com/errata/RHSA-2026:7675",
            "https://access.redhat.com/errata/RHSA-2026:7896",
            "https://access.redhat.com/errata/RHSA-2026:7983",
            "https://access.redhat.com/errata/RHSA-2026:8339",
            "https://access.redhat.com/errata/RHSA-2026:8538",
            "https://access.redhat.com/errata/RHSA-2026:8539",
            "https://access.redhat.com/errata/RHSA-2026:8540",
            "https://access.redhat.com/errata/RHSA-2026:8541",
            "https://access.redhat.com/errata/RHSA-2026:8545",
            "https://access.redhat.com/errata/RHSA-2026:8546",
            "https://access.redhat.com/errata/RHSA-2026:8547",
            "https://access.redhat.com/errata/RHSA-2026:8548",
            "https://access.redhat.com/errata/RHSA-2026:8868",
            "https://access.redhat.com/errata/RHSA-2026:9711",
            "https://access.redhat.com/errata/RHSA-2026:9832",
            "https://access.redhat.com/errata/RHSA-2026:9874",
            "https://access.redhat.com/security/cve/CVE-2026-27135",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2448754",
            "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json"
          ],
          "description": "nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-27135",
              "epss": 0.00775,
              "percentile": 0.52067,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-27135",
              "cwe": "CWE-617",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-27135",
              "cwe": "CWE-617",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "nghttp2",
              "version": "1.52.0-1+deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-27135",
            "versionConstraint": "< 1.52.0-1+deb12u3 (deb)"
          },
          "fix": {
            "suggestedVersion": "1.52.0-1+deb12u3"
          }
        }
      ],
      "artifact": {
        "id": "7fba61587556f31d",
        "name": "libnghttp2-14",
        "version": "1.52.0-1+deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libnghttp2-14",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libnghttp2-14",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2:libnghttp2-14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2:libnghttp2_14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libnghttp2-14@1.52.0-1%2Bdeb12u2?arch=amd64&distro=debian-12&upstream=nghttp2",
        "upstreams": [
          {
            "name": "nghttp2"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-69420",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-69420",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.  Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-69420",
            "epss": 0.00768,
            "percentile": 0.51833,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-69420",
            "cwe": "CWE-754",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.18-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.18-1~deb12u2",
              "date": "2026-01-27",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6113-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6113-1"
          }
        ],
        "risk": 0.5760000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-69420",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-69420",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/27c7012c91cc986a598d7540f3079dfde2416eb9",
            "https://github.com/openssl/openssl/commit/4e254b48ad93cc092be3dd62d97015f33f73133a",
            "https://github.com/openssl/openssl/commit/564fd9c73787f25693bf9e75faf7bf6bb1305d4e",
            "https://github.com/openssl/openssl/commit/5eb0770ffcf11b785cf374ff3c19196245e54f1b",
            "https://github.com/openssl/openssl/commit/a99349ebfc519999edc50620abe24d599b9eb085",
            "https://openssl-library.org/news/secadv/20260127.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response\nverification code where an ASN1_TYPE union member is accessed without first\nvalidating the type, causing an invalid or NULL pointer dereference when\nprocessing a malformed TimeStamp Response file.\n\nImpact summary: An application calling TS_RESP_verify_response() with a\nmalformed TimeStamp Response can be caused to dereference an invalid or\nNULL pointer when reading, resulting in a Denial of Service.\n\nThe functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()\naccess the signing cert attribute value without validating its type.\nWhen the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory\nthrough the ASN1_TYPE union, causing a crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nTimeStamp Response to an application that verifies timestamp responses. The\nTimeStamp protocol (RFC 3161) is not widely used and the impact of the\nexploit is just a Denial of Service. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the TimeStamp Response implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-69420",
              "epss": 0.00768,
              "percentile": 0.51833,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-69420",
              "cwe": "CWE-754",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-69420",
            "versionConstraint": "< 3.0.18-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.18-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5260",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-5260",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.",
        "cvss": [
          {
            "source": "secalert@redhat.com",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "metrics": {
              "baseScore": 8.2,
              "exploitabilityScore": 3.9,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5260",
            "epss": 0.00727,
            "percentile": 0.50443,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5260",
            "cwe": "CWE-126",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 0.570695
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5260",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5260",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:40762",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/security/cve/CVE-2026-5260",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467450",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-10"
          ],
          "description": "A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 8.2,
                "exploitabilityScore": 3.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5260",
              "epss": 0.00727,
              "percentile": 0.50443,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5260",
              "cwe": "CWE-126",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5260",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11856",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-11856",
        "namespace": "debian:distro:debian:12",
        "severity": "Critical",
        "urls": [],
        "description": "Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the  `Authorization:` header field meant for `hostA`, to `hostB`.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 9.8,
              "exploitabilityScore": 3.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-11856",
            "epss": 0.00604,
            "percentile": 0.45386,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11856",
            "cwe": "CWE-294",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.56776
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11856",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-11856.html",
            "https://curl.se/docs/CVE-2026-11856.json",
            "https://hackerone.com/reports/3793260"
          ],
          "description": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11856",
              "epss": 0.00604,
              "percentile": 0.45386,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11856",
              "cwe": "CWE-294",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11856",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42766",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-42766",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present.  An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service.  Applications that process password-encrypted CMS messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42766",
            "epss": 0.00996,
            "percentile": 0.59124,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42766",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.20-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.20-1~deb12u2",
              "date": "2026-06-09",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6335-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6335-1"
          }
        ],
        "risk": 0.54282
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42766",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42766",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce",
            "https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4",
            "https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7",
            "https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4",
            "https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42766",
              "epss": 0.00996,
              "percentile": 0.59124,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42766",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42766",
            "versionConstraint": "< 3.0.20-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.20-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8924",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-8924",
        "namespace": "debian:distro:debian:12",
        "severity": "Critical",
        "urls": [],
        "description": "A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 9.1,
              "exploitabilityScore": 3.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8924",
            "epss": 0.0056,
            "percentile": 0.43302,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.5068
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8924",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-8924.html",
            "https://curl.se/docs/CVE-2026-8924.json",
            "https://hackerone.com/reports/3733905"
          ],
          "description": "A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8924",
              "epss": 0.0056,
              "percentile": 0.43302,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8924",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-7383",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-7383",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow.  Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour.  In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32), and by summing per-character byte counts for UTF8STRING. The calculation overflows when the input reaches around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30 characters) the size wraps to zero, OPENSSL_malloc(1) is called, and the subsequent character copy writes several gigabytes past the one-byte allocation.  X.509 certificate processing routes through ASN1_STRING_set_by_NID(), whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID size limits cap the input length; no network protocol or certificate-handling path in OpenSSL exercises the overflow. Triggering the bug requires an application that calls ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers a custom string type via ASN1_STRING_TABLE_add(), with attacker-controlled input on the order of half a gigabyte or more. For these reasons this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.3,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-7383",
            "epss": 0.0063,
            "percentile": 0.46544,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-7383",
            "cwe": "CWE-787",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.20-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.20-1~deb12u2",
              "date": "2026-06-09",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6335-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6335-1"
          }
        ],
        "risk": 0.4914
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-7383",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-7383",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6",
            "https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74",
            "https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974",
            "https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083",
            "https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.3,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-7383",
              "epss": 0.0063,
              "percentile": 0.46544,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-7383",
              "cwe": "CWE-787",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-7383",
            "versionConstraint": "< 3.0.20-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.20-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-10536",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-10536",
        "namespace": "debian:distro:debian:12",
        "severity": "Critical",
        "urls": [],
        "description": "A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 9.8,
              "exploitabilityScore": 3.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-10536",
            "epss": 0.00507,
            "percentile": 0.40374,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-10536",
            "cwe": "CWE-416",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.47657999999999995
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-10536",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-10536",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-10536.html",
            "https://curl.se/docs/CVE-2026-10536.json",
            "https://hackerone.com/reports/3751697"
          ],
          "description": "A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-10536",
              "epss": 0.00507,
              "percentile": 0.40374,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-10536",
              "cwe": "CWE-416",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-10536",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5450",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-5450",
        "namespace": "debian:distro:debian:12",
        "severity": "Critical",
        "urls": [],
        "description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 9.8,
              "exploitabilityScore": 3.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5450",
            "epss": 0.00502,
            "percentile": 0.40088,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5450",
            "cwe": "CWE-122",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-5450",
            "cwe": "CWE-787",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.47188
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5450",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5450",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5450",
              "epss": 0.00502,
              "percentile": 0.40088,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5450",
              "cwe": "CWE-122",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-5450",
              "cwe": "CWE-787",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5450",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5773",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-5773",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different 'share' than the new subsequent transfer should.  This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5773",
            "epss": 0.00618,
            "percentile": 0.46036,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5773",
            "cwe": "CWE-918",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [
            "7.88.1-10+deb12u15"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "7.88.1-10+deb12u15",
              "date": "2026-07-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.4635
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5773",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-5773.html",
            "https://curl.se/docs/CVE-2026-5773.json",
            "https://hackerone.com/reports/3650689",
            "http://www.openwall.com/lists/oss-security/2026/04/29/9"
          ],
          "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5773",
              "epss": 0.00618,
              "percentile": 0.46036,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5773",
              "cwe": "CWE-918",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5773",
            "versionConstraint": "< 7.88.1-10+deb12u15 (deb)"
          },
          "fix": {
            "suggestedVersion": "7.88.1-10+deb12u15"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40355",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-40355",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40355",
            "epss": 0.00611,
            "percentile": 0.45653,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40355",
            "cwe": "CWE-476",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1.20.1-2+deb12u5"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1.20.1-2+deb12u5",
              "date": "2026-05-22",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6293-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6293-1"
          }
        ],
        "risk": 0.45825
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40355",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40355",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html",
            "https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f",
            "https://web.mit.edu/kerberos/advisories/",
            "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40355",
              "epss": 0.00611,
              "percentile": 0.45653,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40355",
              "cwe": "CWE-476",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40355",
            "versionConstraint": "< 1.20.1-2+deb12u5 (deb)"
          },
          "fix": {
            "suggestedVersion": "1.20.1-2+deb12u5"
          }
        }
      ],
      "artifact": {
        "id": "c8948b00cda8062b",
        "name": "libgssapi-krb5-2",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40355",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-40355",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40355",
            "epss": 0.00611,
            "percentile": 0.45653,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40355",
            "cwe": "CWE-476",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1.20.1-2+deb12u5"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1.20.1-2+deb12u5",
              "date": "2026-05-22",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6293-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6293-1"
          }
        ],
        "risk": 0.45825
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40355",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40355",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html",
            "https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f",
            "https://web.mit.edu/kerberos/advisories/",
            "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40355",
              "epss": 0.00611,
              "percentile": 0.45653,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40355",
              "cwe": "CWE-476",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40355",
            "versionConstraint": "< 1.20.1-2+deb12u5 (deb)"
          },
          "fix": {
            "suggestedVersion": "1.20.1-2+deb12u5"
          }
        }
      ],
      "artifact": {
        "id": "8f3a478cb18888b8",
        "name": "libk5crypto3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libk5crypto3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libk5crypto3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40355",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-40355",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40355",
            "epss": 0.00611,
            "percentile": 0.45653,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40355",
            "cwe": "CWE-476",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1.20.1-2+deb12u5"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1.20.1-2+deb12u5",
              "date": "2026-05-22",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6293-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6293-1"
          }
        ],
        "risk": 0.45825
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40355",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40355",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html",
            "https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f",
            "https://web.mit.edu/kerberos/advisories/",
            "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40355",
              "epss": 0.00611,
              "percentile": 0.45653,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40355",
              "cwe": "CWE-476",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40355",
            "versionConstraint": "< 1.20.1-2+deb12u5 (deb)"
          },
          "fix": {
            "suggestedVersion": "1.20.1-2+deb12u5"
          }
        }
      ],
      "artifact": {
        "id": "575c8aeb7addaf05",
        "name": "libkrb5-3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5-3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5-3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40355",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-40355",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40355",
            "epss": 0.00611,
            "percentile": 0.45653,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40355",
            "cwe": "CWE-476",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1.20.1-2+deb12u5"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1.20.1-2+deb12u5",
              "date": "2026-05-22",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6293-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6293-1"
          }
        ],
        "risk": 0.45825
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40355",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40355",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html",
            "https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f",
            "https://web.mit.edu/kerberos/advisories/",
            "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40355",
              "epss": 0.00611,
              "percentile": 0.45653,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40355",
              "cwe": "CWE-476",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40355",
            "versionConstraint": "< 1.20.1-2+deb12u5 (deb)"
          },
          "fix": {
            "suggestedVersion": "1.20.1-2+deb12u5"
          }
        }
      ],
      "artifact": {
        "id": "f17cb326c34696aa",
        "name": "libkrb5support0",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5support0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5support0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40356",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-40356",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40356",
            "epss": 0.00604,
            "percentile": 0.45359,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40356",
            "cwe": "CWE-191",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1.20.1-2+deb12u5"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1.20.1-2+deb12u5",
              "date": "2026-05-22",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6293-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6293-1"
          }
        ],
        "risk": 0.453
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40356",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40356",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html",
            "https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f",
            "https://web.mit.edu/kerberos/advisories/"
          ],
          "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40356",
              "epss": 0.00604,
              "percentile": 0.45359,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40356",
              "cwe": "CWE-191",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40356",
            "versionConstraint": "< 1.20.1-2+deb12u5 (deb)"
          },
          "fix": {
            "suggestedVersion": "1.20.1-2+deb12u5"
          }
        }
      ],
      "artifact": {
        "id": "c8948b00cda8062b",
        "name": "libgssapi-krb5-2",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40356",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-40356",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40356",
            "epss": 0.00604,
            "percentile": 0.45359,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40356",
            "cwe": "CWE-191",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1.20.1-2+deb12u5"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1.20.1-2+deb12u5",
              "date": "2026-05-22",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6293-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6293-1"
          }
        ],
        "risk": 0.453
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40356",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40356",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html",
            "https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f",
            "https://web.mit.edu/kerberos/advisories/"
          ],
          "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40356",
              "epss": 0.00604,
              "percentile": 0.45359,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40356",
              "cwe": "CWE-191",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40356",
            "versionConstraint": "< 1.20.1-2+deb12u5 (deb)"
          },
          "fix": {
            "suggestedVersion": "1.20.1-2+deb12u5"
          }
        }
      ],
      "artifact": {
        "id": "8f3a478cb18888b8",
        "name": "libk5crypto3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libk5crypto3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libk5crypto3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40356",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-40356",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40356",
            "epss": 0.00604,
            "percentile": 0.45359,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40356",
            "cwe": "CWE-191",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1.20.1-2+deb12u5"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1.20.1-2+deb12u5",
              "date": "2026-05-22",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6293-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6293-1"
          }
        ],
        "risk": 0.453
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40356",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40356",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html",
            "https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f",
            "https://web.mit.edu/kerberos/advisories/"
          ],
          "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40356",
              "epss": 0.00604,
              "percentile": 0.45359,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40356",
              "cwe": "CWE-191",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40356",
            "versionConstraint": "< 1.20.1-2+deb12u5 (deb)"
          },
          "fix": {
            "suggestedVersion": "1.20.1-2+deb12u5"
          }
        }
      ],
      "artifact": {
        "id": "575c8aeb7addaf05",
        "name": "libkrb5-3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5-3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5-3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40356",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-40356",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40356",
            "epss": 0.00604,
            "percentile": 0.45359,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40356",
            "cwe": "CWE-191",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1.20.1-2+deb12u5"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1.20.1-2+deb12u5",
              "date": "2026-05-22",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6293-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6293-1"
          }
        ],
        "risk": 0.453
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40356",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40356",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html",
            "https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f",
            "https://web.mit.edu/kerberos/advisories/"
          ],
          "description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40356",
              "epss": 0.00604,
              "percentile": 0.45359,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40356",
              "cwe": "CWE-191",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40356",
            "versionConstraint": "< 1.20.1-2+deb12u5 (deb)"
          },
          "fix": {
            "suggestedVersion": "1.20.1-2+deb12u5"
          }
        }
      ],
      "artifact": {
        "id": "f17cb326c34696aa",
        "name": "libkrb5support0",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5support0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5support0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-45445",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-45445",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded.  Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality.  If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message.  OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex().  The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not.  Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV.  If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext.  The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair.  The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-45445",
            "epss": 0.00603,
            "percentile": 0.4534,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-45445",
            "cwe": "CWE-325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.20-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.20-1~deb12u2",
              "date": "2026-06-09",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6335-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6335-1"
          }
        ],
        "risk": 0.45225
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-45445",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-45445",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451",
            "https://github.com/openssl/openssl/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7",
            "https://github.com/openssl/openssl/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af",
            "https://github.com/openssl/openssl/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c",
            "https://github.com/openssl/openssl/commit/983d54b5cce8d16147548ed1a37892d1720bbab6",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: When an application drives an AES-OCB context through the\npublic EVP_Cipher() one-shot interface, the application-supplied\ninitialisation vector (IV) is silently discarded.\n\nImpact summary: Every message encrypted under the same key uses the\nsame effective nonce regardless of the IV supplied by the caller,\nresulting in (key, nonce) reuse and loss of confidentiality.  If the\nsame code path is used to compute the authentication tag, the tag\ndepends only on the (key, IV) pair and not on the plaintext or\nciphertext, allowing universal forgery of arbitrary ciphertext from a\nsingle captured message.\n\nOpenSSL provides two ways to drive a cipher: the documented streaming\ninterface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level\none-shot, EVP_Cipher(), whose documentation explicitly recommends\nagainst use by applications in favour of EVP_CipherUpdate() and\nEVP_CipherFinal_ex().  The OCB provider's streaming handler flushes\nthe application-supplied IV into the OCB context before processing\ndata; the one-shot handler did not.  Every call to EVP_Cipher() on an\nAES-OCB context therefore ran with the all-zero key-derived offset\nstate left by cipher initialisation, regardless of the caller's IV.\n\nIf EVP_EncryptFinal_ex() is subsequently used to obtain the\nauthentication tag, the deferred IV setup runs at that point and\nclears the running checksum that should have been accumulated over the\nplaintext.  The resulting tag is a function of (key, IV) only and\nverifies against any ciphertext produced under the same (key, IV)\npair.\n\nThe OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a\nTLS cipher suite, and libssl does not call EVP_Cipher() in any case.\nApplications that drive AES-OCB through the documented streaming AEAD\nAPI (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only\napplications that combine the AES-OCB cipher with the EVP_Cipher()\none-shot API are vulnerable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-45445",
              "epss": 0.00603,
              "percentile": 0.4534,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-45445",
              "cwe": "CWE-325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-45445",
            "versionConstraint": "< 3.0.20-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.20-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-9076",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-9076",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key().  Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker.  The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen.  Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds.  The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator.  The FIPS modules are not affected by this issue.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-9076",
            "epss": 0.00589,
            "percentile": 0.44671,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-9076",
            "cwe": "CWE-125",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.20-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.20-1~deb12u2",
              "date": "2026-06-09",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6335-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6335-1"
          }
        ],
        "risk": 0.44175000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-9076",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-9076",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb",
            "https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0",
            "https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98",
            "https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26",
            "https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-9076",
              "epss": 0.00589,
              "percentile": 0.44671,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-9076",
              "cwe": "CWE-125",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-9076",
            "versionConstraint": "< 3.0.20-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.20-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6478",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6478",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate.  This does not affect scram-sha-256 passwords, the default in all supported releases.  However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
            "metrics": {
              "baseScore": 8.2,
              "exploitabilityScore": 3.9,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6478",
            "epss": 0.00558,
            "percentile": 0.43207,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6478",
            "cwe": "CWE-385",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-6478",
            "cwe": "CWE-385",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.18-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.18-0+deb12u1",
              "date": "2026-05-14",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6269-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6269-1"
          }
        ],
        "risk": 0.4380299999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6478",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6478",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-6478/",
            "https://access.redhat.com/errata/RHSA-2026:21182",
            "https://access.redhat.com/errata/RHSA-2026:22878",
            "https://access.redhat.com/errata/RHSA-2026:26181",
            "https://access.redhat.com/errata/RHSA-2026:26203",
            "https://access.redhat.com/errata/RHSA-2026:26204",
            "https://access.redhat.com/errata/RHSA-2026:26524",
            "https://access.redhat.com/errata/RHSA-2026:26525",
            "https://access.redhat.com/errata/RHSA-2026:26561",
            "https://access.redhat.com/errata/RHSA-2026:27718",
            "https://access.redhat.com/errata/RHSA-2026:27738",
            "https://access.redhat.com/errata/RHSA-2026:27741",
            "https://access.redhat.com/errata/RHSA-2026:27742",
            "https://access.redhat.com/errata/RHSA-2026:27743",
            "https://access.redhat.com/errata/RHSA-2026:28037",
            "https://access.redhat.com/errata/RHSA-2026:28143",
            "https://access.redhat.com/errata/RHSA-2026:28208",
            "https://access.redhat.com/errata/RHSA-2026:28999",
            "https://access.redhat.com/errata/RHSA-2026:29212",
            "https://access.redhat.com/errata/RHSA-2026:29815",
            "https://access.redhat.com/errata/RHSA-2026:29904",
            "https://access.redhat.com/errata/RHSA-2026:29953",
            "https://access.redhat.com/errata/RHSA-2026:32983",
            "https://access.redhat.com/errata/RHSA-2026:32994",
            "https://access.redhat.com/errata/RHSA-2026:33441",
            "https://access.redhat.com/errata/RHSA-2026:33497",
            "https://access.redhat.com/errata/RHSA-2026:34043",
            "https://access.redhat.com/errata/RHSA-2026:34362",
            "https://access.redhat.com/errata/RHSA-2026:34363",
            "https://access.redhat.com/errata/RHSA-2026:35880",
            "https://access.redhat.com/errata/RHSA-2026:42555",
            "https://access.redhat.com/errata/RHSA-2026:44420",
            "https://access.redhat.com/errata/RHSA-2026:44481",
            "https://access.redhat.com/security/cve/CVE-2026-6478",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2477447",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6478.json"
          ],
          "description": "Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate.  This does not affect scram-sha-256 passwords, the default in all supported releases.  However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
              "metrics": {
                "baseScore": 8.2,
                "exploitabilityScore": 3.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6478",
              "epss": 0.00558,
              "percentile": 0.43207,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6478",
              "cwe": "CWE-385",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-6478",
              "cwe": "CWE-385",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6478",
            "versionConstraint": "< 15.18-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.18-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-0915",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-0915",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-0915",
            "epss": 0.00564,
            "percentile": 0.43527,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-0915",
            "cwe": "CWE-908",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "2.36-9+deb12u14"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "2.36-9+deb12u14",
              "date": "2026-05-17",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.42300000000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-0915",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-0915",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=33802",
            "http://www.openwall.com/lists/oss-security/2026/01/16/6"
          ],
          "description": "Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-0915",
              "epss": 0.00564,
              "percentile": 0.43527,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-0915",
              "cwe": "CWE-908",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-0915",
            "versionConstraint": "< 2.36-9+deb12u14 (deb)"
          },
          "fix": {
            "suggestedVersion": "2.36-9+deb12u14"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-7598",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-7598",
        "namespace": "debian:distro:debian:12",
        "severity": "Critical",
        "urls": [],
        "description": "A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "metrics": {
              "baseScore": 9.1,
              "exploitabilityScore": 3.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-7598",
            "epss": 0.00466,
            "percentile": 0.37866,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-7598",
            "cwe": "CWE-189",
            "source": "cna@vuldb.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-7598",
            "cwe": "CWE-190",
            "source": "cna@vuldb.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-7598",
            "cwe": "CWE-190",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.42173000000000005
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-7598",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-7598",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://github.com/libssh2/libssh2/",
            "https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1",
            "https://github.com/libssh2/libssh2/pull/1858",
            "https://vuldb.com/submit/805564",
            "https://vuldb.com/vuln/360555",
            "https://vuldb.com/vuln/360555/cti",
            "https://access.redhat.com/errata/RHSA-2026:16736",
            "https://access.redhat.com/errata/RHSA-2026:7021",
            "https://access.redhat.com/security/cve/CVE-2026-7598",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2464597",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7598.json"
          ],
          "description": "A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "cna@vuldb.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 6.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "cna@vuldb.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 7.3,
                "exploitabilityScore": 3.9,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            },
            {
              "source": "cna@vuldb.com",
              "type": "Secondary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 10,
                "impactScore": 6.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-7598",
              "epss": 0.00466,
              "percentile": 0.37866,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-7598",
              "cwe": "CWE-189",
              "source": "cna@vuldb.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-7598",
              "cwe": "CWE-190",
              "source": "cna@vuldb.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-7598",
              "cwe": "CWE-190",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libssh2",
              "version": "1.10.0-3"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-7598",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8905b74027385650",
        "name": "libssh2-1",
        "version": "1.10.0-3+b1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssh2-1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssh2-1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12&upstream=libssh2%401.10.0-3",
        "upstreams": [
          {
            "name": "libssh2",
            "version": "1.10.0-3"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-3833",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-3833",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 7.4,
              "exploitabilityScore": 2.3,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-3833",
            "epss": 0.00565,
            "percentile": 0.4357,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-3833",
            "cwe": "CWE-178",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 0.42092499999999994
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-3833",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-3833",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-3833",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2445763",
            "https://gitlab.com/gnutls/gnutls/-/issues/1803"
          ],
          "description": "A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.4,
                "exploitabilityScore": 2.3,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-3833",
              "epss": 0.00565,
              "percentile": 0.4357,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-3833",
              "cwe": "CWE-178",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-3833",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8927",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-8927",
        "namespace": "debian:distro:debian:12",
        "severity": "Critical",
        "urls": [],
        "description": "When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 9.1,
              "exploitabilityScore": 3.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8927",
            "epss": 0.0044,
            "percentile": 0.36048,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-8927",
            "cwe": "CWE-294",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.39820000000000005
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8927",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8927",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://curl.se/docs/CVE-2026-8927.html",
            "https://curl.se/docs/CVE-2026-8927.json",
            "https://hackerone.com/reports/3744543"
          ],
          "description": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8927",
              "epss": 0.0044,
              "percentile": 0.36048,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-8927",
              "cwe": "CWE-294",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8927",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6253",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6253",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6253",
            "epss": 0.00719,
            "percentile": 0.50163,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6253",
            "cwe": "CWE-522",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.39185500000000006
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6253",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-6253.html",
            "https://curl.se/docs/CVE-2026-6253.json",
            "https://hackerone.com/reports/3669637",
            "http://www.openwall.com/lists/oss-security/2026/04/29/11"
          ],
          "description": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6253",
              "epss": 0.00719,
              "percentile": 0.50163,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6253",
              "cwe": "CWE-522",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6253",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-12972",
        "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-12972",
        "namespace": "nvd:cpe",
        "severity": "Medium",
        "urls": [
          "https://fluentbit.io/blog/2025/10/28/security-vulnerabilities-addressed-in-fluent-bit-v4.1-and-backported-to-v4.0/",
          "https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover"
        ],
        "description": "Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Fluent Bit to write files outside the intended output directory.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-12972",
            "epss": 0.00734,
            "percentile": 0.50715,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-12972",
            "cwe": "CWE-22",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": ""
        },
        "advisories": [],
        "risk": 0.37801
      },
      "relatedVulnerabilities": [],
      "matchDetails": [
        {
          "type": "cpe-match",
          "matcher": "stock-matcher",
          "searchedBy": {
            "namespace": "nvd:cpe",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
            ],
            "package": {
              "name": "fluent-bit",
              "version": "4.1.0"
            }
          },
          "found": {
            "vulnerabilityID": "CVE-2025-12972",
            "versionConstraint": "= 4.1.0 (unknown)",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*"
            ]
          }
        }
      ],
      "artifact": {
        "id": "c9f8017f4b3fb0ab",
        "name": "fluent-bit",
        "version": "4.1.0",
        "type": "binary",
        "locations": [
          {
            "path": "/fluent-bit/bin/fluent-bit",
            "layerID": "sha256:0f3590c76e91ee02acf305bdcff2f981bc9f783070524382028f071e8da36d86",
            "accessPath": "/fluent-bit/bin/fluent-bit",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:github/fluent/fluent-bit@4.1.0",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42015",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-42015",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.",
        "cvss": [
          {
            "source": "secalert@redhat.com",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42015",
            "epss": 0.00727,
            "percentile": 0.50439,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42015",
            "cwe": "CWE-193",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 0.37440500000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42015",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42015",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-42015",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467678",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-11"
          ],
          "description": "A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42015",
              "epss": 0.00727,
              "percentile": 0.50439,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42015",
              "cwe": "CWE-193",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42015",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6477",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6477",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response.  Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size.  Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
        "cvss": [
          {
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.4,
              "exploitabilityScore": 1.7,
              "impactScore": 6.1
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6477",
            "epss": 0.00454,
            "percentile": 0.37112,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6477",
            "cwe": "CWE-242",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-6477",
            "cwe": "CWE-120",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.18-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.18-0+deb12u1",
              "date": "2026-05-14",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6269-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6269-1"
          }
        ],
        "risk": 0.36093000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6477",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6477",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-6477/",
            "https://access.redhat.com/errata/RHSA-2026:21182",
            "https://access.redhat.com/errata/RHSA-2026:22878",
            "https://access.redhat.com/errata/RHSA-2026:26181",
            "https://access.redhat.com/errata/RHSA-2026:26203",
            "https://access.redhat.com/errata/RHSA-2026:26204",
            "https://access.redhat.com/errata/RHSA-2026:26524",
            "https://access.redhat.com/errata/RHSA-2026:26525",
            "https://access.redhat.com/errata/RHSA-2026:26561",
            "https://access.redhat.com/errata/RHSA-2026:27718",
            "https://access.redhat.com/errata/RHSA-2026:27738",
            "https://access.redhat.com/errata/RHSA-2026:27741",
            "https://access.redhat.com/errata/RHSA-2026:27742",
            "https://access.redhat.com/errata/RHSA-2026:27743",
            "https://access.redhat.com/errata/RHSA-2026:28037",
            "https://access.redhat.com/errata/RHSA-2026:28143",
            "https://access.redhat.com/errata/RHSA-2026:28208",
            "https://access.redhat.com/errata/RHSA-2026:28999",
            "https://access.redhat.com/errata/RHSA-2026:29212",
            "https://access.redhat.com/errata/RHSA-2026:29815",
            "https://access.redhat.com/errata/RHSA-2026:29904",
            "https://access.redhat.com/errata/RHSA-2026:29953",
            "https://access.redhat.com/errata/RHSA-2026:32983",
            "https://access.redhat.com/errata/RHSA-2026:32994",
            "https://access.redhat.com/errata/RHSA-2026:33441",
            "https://access.redhat.com/errata/RHSA-2026:33497",
            "https://access.redhat.com/errata/RHSA-2026:34043",
            "https://access.redhat.com/errata/RHSA-2026:34362",
            "https://access.redhat.com/errata/RHSA-2026:34363",
            "https://access.redhat.com/errata/RHSA-2026:35880",
            "https://access.redhat.com/errata/RHSA-2026:42555",
            "https://access.redhat.com/errata/RHSA-2026:44308",
            "https://access.redhat.com/errata/RHSA-2026:44391",
            "https://access.redhat.com/errata/RHSA-2026:44420",
            "https://access.redhat.com/errata/RHSA-2026:44481",
            "https://access.redhat.com/security/cve/CVE-2026-6477",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2477442",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6477.json"
          ],
          "description": "Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response.  Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size.  Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
          "cvss": [
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.4,
                "exploitabilityScore": 1.7,
                "impactScore": 6.1
              },
              "vendorMetadata": {}
            },
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6477",
              "epss": 0.00454,
              "percentile": 0.37112,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6477",
              "cwe": "CWE-242",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-6477",
              "cwe": "CWE-120",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6477",
            "versionConstraint": "< 15.18-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.18-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-12969",
        "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-12969",
        "namespace": "nvd:cpe",
        "severity": "Medium",
        "urls": [
          "https://fluentbit.io/blog/2025/10/28/security-vulnerabilities-addressed-in-fluent-bit-v4.1-and-backported-to-v4.0/",
          "https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover"
        ],
        "description": "Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authentication controls, attackers can inject forged log records, flood alerting systems, or manipulate routing decisions, compromising the authenticity and integrity of ingested logs.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-12969",
            "epss": 0.00621,
            "percentile": 0.46175,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-12969",
            "cwe": "CWE-306",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": ""
        },
        "advisories": [],
        "risk": 0.357075
      },
      "relatedVulnerabilities": [],
      "matchDetails": [
        {
          "type": "cpe-match",
          "matcher": "stock-matcher",
          "searchedBy": {
            "namespace": "nvd:cpe",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
            ],
            "package": {
              "name": "fluent-bit",
              "version": "4.1.0"
            }
          },
          "found": {
            "vulnerabilityID": "CVE-2025-12969",
            "versionConstraint": "= 4.1.0 (unknown)",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*"
            ]
          }
        }
      ],
      "artifact": {
        "id": "c9f8017f4b3fb0ab",
        "name": "fluent-bit",
        "version": "4.1.0",
        "type": "binary",
        "locations": [
          {
            "path": "/fluent-bit/bin/fluent-bit",
            "layerID": "sha256:0f3590c76e91ee02acf305bdcff2f981bc9f783070524382028f071e8da36d86",
            "accessPath": "/fluent-bit/bin/fluent-bit",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:github/fluent/fluent-bit@4.1.0",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42011",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-42011",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.",
        "cvss": [
          {
            "source": "secalert@redhat.com",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 7.4,
              "exploitabilityScore": 2.3,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42011",
            "epss": 0.00475,
            "percentile": 0.38466,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42011",
            "cwe": "CWE-295",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 0.353875
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42011",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42011",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:40762",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-42011",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467437",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-6"
          ],
          "description": "A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.4,
                "exploitabilityScore": 2.3,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42011",
              "epss": 0.00475,
              "percentile": 0.38466,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42011",
              "cwe": "CWE-295",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42011",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6479",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6479",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service.  If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
        "cvss": [
          {
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6479",
            "epss": 0.00471,
            "percentile": 0.38136,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6479",
            "cwe": "CWE-674",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.18-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.18-0+deb12u1",
              "date": "2026-05-14",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6269-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6269-1"
          }
        ],
        "risk": 0.35325
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6479",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6479",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-6479/"
          ],
          "description": "Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service.  If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
          "cvss": [
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6479",
              "epss": 0.00471,
              "percentile": 0.38136,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6479",
              "cwe": "CWE-674",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6479",
            "versionConstraint": "< 15.18-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.18-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2017-17740",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2017-17740",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2017-17740",
            "epss": 0.07022,
            "percentile": 0.93502,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2017-17740",
            "cwe": "CWE-119",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.3511
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2017-17740",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2017-17740",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html",
            "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html",
            "http://www.openldap.org/its/index.cgi/Incoming?id=8759",
            "https://kc.mcafee.com/corporate/index?page=content&id=SB10365",
            "https://www.oracle.com/security-alerts/cpuapr2022.html"
          ],
          "description": "contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 10,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2017-17740",
              "epss": 0.07022,
              "percentile": 0.93502,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2017-17740",
              "cwe": "CWE-119",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openldap",
              "version": "2.5.13+dfsg-5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2017-17740",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "919a44d8cbaa32e2",
        "name": "libldap-2.5-0",
        "version": "2.5.13+dfsg-5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12&upstream=openldap",
        "upstreams": [
          {
            "name": "openldap"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-14819",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-14819",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "When doing TLS related transfers with reused easy or multi handles and altering the  `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.7,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-14819",
            "epss": 0.00679,
            "percentile": 0.4866,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-14819",
            "cwe": "CWE-295",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "7.88.1-10+deb12u15"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "7.88.1-10+deb12u15",
              "date": "2026-07-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.349685
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-14819",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-14819",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-14819.html",
            "https://curl.se/docs/CVE-2025-14819.json",
            "http://www.openwall.com/lists/oss-security/2026/01/07/5"
          ],
          "description": "When doing TLS related transfers with reused easy or multi handles and\naltering the  `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally\nreuse a CA store cached in memory for which the partial chain option was\nreversed. Contrary to the user's wishes and expectations. This could make\nlibcurl find and accept a trust chain that it otherwise would not.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-14819",
              "epss": 0.00679,
              "percentile": 0.4866,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-14819",
              "cwe": "CWE-295",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-14819",
            "versionConstraint": "< 7.88.1-10+deb12u15 (deb)"
          },
          "fix": {
            "suggestedVersion": "7.88.1-10+deb12u15"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42013",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-42013",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.",
        "cvss": [
          {
            "source": "secalert@redhat.com",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "metrics": {
              "baseScore": 8.2,
              "exploitabilityScore": 3.9,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42013",
            "epss": 0.00423,
            "percentile": 0.34714,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42013",
            "cwe": "CWE-295",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 0.332055
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42013",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42013",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:40762",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-42013",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467448",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-8"
          ],
          "description": "A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
              "metrics": {
                "baseScore": 8.2,
                "exploitabilityScore": 3.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42013",
              "epss": 0.00423,
              "percentile": 0.34714,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42013",
              "cwe": "CWE-295",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42013",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-69419",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-69419",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.  Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.  The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer.  The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 7.4,
              "exploitabilityScore": 2.3,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-69419",
            "epss": 0.00444,
            "percentile": 0.36402,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-69419",
            "cwe": "CWE-787",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.18-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.18-1~deb12u2",
              "date": "2026-01-27",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6113-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6113-1"
          }
        ],
        "risk": 0.33078
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-69419",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-69419",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/openssl/openssl/commit/41be0f216404f14457bbf3b9cc488dba60b49296",
            "https://github.com/openssl/openssl/commit/7e9cac9832e4705b91987c2474ed06a37a93cecb",
            "https://github.com/openssl/openssl/commit/a26a90d38edec3748566129d824e664b54bee2e2",
            "https://github.com/openssl/openssl/commit/cda12de3bc0e333ea8d2c6fd15001dbdaf280015",
            "https://github.com/openssl/openssl/commit/ff628933755075446bca8307e8417c14d164b535",
            "https://openssl-library.org/news/secadv/20260127.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously\ncrafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing\nnon-ASCII BMP code point can trigger a one byte write before the allocated\nbuffer.\n\nImpact summary: The out-of-bounds write can cause a memory corruption\nwhich can have various consequences including a Denial of Service.\n\nThe OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12\nBMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes,\nthe helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16\nsource byte count as the destination buffer capacity to UTF8_putc(). For BMP\ncode points above U+07FF, UTF-8 requires three bytes, but the forwarded\ncapacity can be just two bytes. UTF8_putc() then returns -1, and this negative\nvalue is added to the output length without validation, causing the\nlength to become negative. The subsequent trailing NUL byte is then written\nat a negative offset, causing write outside of heap allocated buffer.\n\nThe vulnerability is reachable via the public PKCS12_get_friendlyname() API\nwhen parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a\ndifferent code path that avoids this issue, PKCS12_get_friendlyname() directly\ninvokes the vulnerable function. Exploitation requires an attacker to provide\na malicious PKCS#12 file to be parsed by the application and the attacker\ncan just trigger a one zero byte write before the allocated buffer.\nFor that reason the issue was assessed as Low severity according to our\nSecurity Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.4,
                "exploitabilityScore": 2.3,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-69419",
              "epss": 0.00444,
              "percentile": 0.36402,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-69419",
              "cwe": "CWE-787",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-69419",
            "versionConstraint": "< 3.0.18-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.18-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-15281",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-15281",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-15281",
            "epss": 0.00439,
            "percentile": 0.36004,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-15281",
            "cwe": "CWE-908",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "2.36-9+deb12u14"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "2.36-9+deb12u14",
              "date": "2026-05-17",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.32925
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-15281",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-15281",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=33814",
            "http://www.openwall.com/lists/oss-security/2026/01/20/3"
          ],
          "description": "Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-15281",
              "epss": 0.00439,
              "percentile": 0.36004,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-15281",
              "cwe": "CWE-908",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-15281",
            "versionConstraint": "< 2.36-9+deb12u14 (deb)"
          },
          "fix": {
            "suggestedVersion": "2.36-9+deb12u14"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-14831",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-14831",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).",
        "cvss": [
          {
            "source": "secalert@redhat.com",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-14831",
            "epss": 0.00638,
            "percentile": 0.46913,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-14831",
            "cwe": "CWE-407",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u6"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u6",
              "date": "2026-02-18",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6140-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6140-1"
          }
        ],
        "risk": 0.32857000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-14831",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-14831",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13812",
            "https://access.redhat.com/errata/RHSA-2026:16008",
            "https://access.redhat.com/errata/RHSA-2026:16009",
            "https://access.redhat.com/errata/RHSA-2026:16174",
            "https://access.redhat.com/errata/RHSA-2026:25096",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:3477",
            "https://access.redhat.com/errata/RHSA-2026:4188",
            "https://access.redhat.com/errata/RHSA-2026:4655",
            "https://access.redhat.com/errata/RHSA-2026:4943",
            "https://access.redhat.com/errata/RHSA-2026:5585",
            "https://access.redhat.com/errata/RHSA-2026:5606",
            "https://access.redhat.com/errata/RHSA-2026:6618",
            "https://access.redhat.com/errata/RHSA-2026:6630",
            "https://access.redhat.com/errata/RHSA-2026:6737",
            "https://access.redhat.com/errata/RHSA-2026:6738",
            "https://access.redhat.com/errata/RHSA-2026:7329",
            "https://access.redhat.com/errata/RHSA-2026:7335",
            "https://access.redhat.com/errata/RHSA-2026:7477",
            "https://access.redhat.com/errata/RHSA-2026:8746",
            "https://access.redhat.com/errata/RHSA-2026:8747",
            "https://access.redhat.com/errata/RHSA-2026:8748",
            "https://access.redhat.com/security/cve/CVE-2025-14831",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2423177",
            "https://gitlab.com/gnutls/gnutls/-/issues/1773",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-14831",
              "epss": 0.00638,
              "percentile": 0.46913,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-14831",
              "cwe": "CWE-407",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-14831",
            "versionConstraint": "< 3.7.9-2+deb12u6 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u6"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34182",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-34182",
        "namespace": "debian:distro:debian:12",
        "severity": "Critical",
        "urls": [],
        "description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises.  Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message.  In one use case, an attacker may send a CMS message containing AuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL erroneously allows this selection, and attempts to decrypt and validate the message.  An on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData addressed to the victim can re-emit it with the recipientInfos set left byte-for-byte intact, so the victim's private key still unwraps the genuine CEK (the content-encryption key), but with the inner OID rewritten to AES-256-OFB (Output Feedback Mode, an unauthenticated keystream mode) and with an attacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the real CEK, never consults the MAC field, and CMS_decrypt() returns success.  If the application under attack responds to the attacker with any indicator showing success or failure of the decryption effort, it is possible for the attacker to use this as an oracle to obtain key equivalent functionality for the CEK used for the chosen recipient of the message.  In another use case, an attacker can reduce the tag length of the chosen AEAD cipher for a given AuthEnvelopedData container to be a single byte long, allowing an attacker to brute force CMS decryption, producing an integrity bypass for applications that trust CMS_decrypt() to reject modified content.  The FIPS modules are not affected by this issue.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 9.1,
              "exploitabilityScore": 3.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34182",
            "epss": 0.0035,
            "percentile": 0.27658,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34182",
            "cwe": "CWE-354",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.20-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.20-1~deb12u2",
              "date": "2026-06-09",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6335-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6335-1"
          }
        ],
        "risk": 0.31675000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34182",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34182",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://github.com/openssl/openssl/commit/03c1f4d45fb963aee7d5833390c507cd290182bc",
            "https://github.com/openssl/openssl/commit/439ed7d2c0962ce964482727264668bf277c333f",
            "https://github.com/openssl/openssl/commit/7947e6a81eb8776802f159fb6762cb7fcf7e34c7",
            "https://github.com/openssl/openssl/commit/9fd97f8cfdc2c0be214998de3b2b55c8edf6c7ac",
            "https://github.com/openssl/openssl/commit/d2ca86bcd43e4f17d899f347101766b6107676e0",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform\nsufficient input validation on the cipher and tag length fields of\nAuthEnvelopedData containers, leading to various potential compromises.\n\nImpact Summary: Attackers making use of these vulnerabilities may achieve\nkey-equivalent functionality for a given CMS recipient and/or bypass integrity\nvalidation for a given message.\n\nIn one use case, an attacker may send a CMS message containing\nAuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL\nerroneously allows this selection, and attempts to decrypt and validate the\nmessage.\n\nAn on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData\naddressed to the victim can re-emit it with the recipientInfos set left\nbyte-for-byte intact, so the victim's private key still unwraps the genuine CEK\n(the content-encryption key), but with the inner OID rewritten to AES-256-OFB\n(Output Feedback Mode, an unauthenticated keystream mode) and with an\nattacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the\nreal CEK, never consults the MAC field, and CMS_decrypt() returns success.\n\nIf the application under attack responds to the attacker with any indicator\nshowing success or failure of the decryption effort, it is possible for the\nattacker to use this as an oracle to obtain key equivalent functionality for the\nCEK used for the chosen recipient of the message.\n\nIn another use case, an attacker can reduce the tag length of the chosen AEAD\ncipher for a given AuthEnvelopedData container to be a single byte long,\nallowing an attacker to brute force CMS decryption, producing an integrity\nbypass for applications that trust CMS_decrypt() to reject modified content.\n\nThe FIPS modules are not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 9.1,
                "exploitabilityScore": 3.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34182",
              "epss": 0.0035,
              "percentile": 0.27658,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34182",
              "cwe": "CWE-354",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34182",
            "versionConstraint": "< 3.0.20-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.20-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-14524",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-14524",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.7,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-14524",
            "epss": 0.00611,
            "percentile": 0.45702,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-14524",
            "cwe": "CWE-601",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [
            "7.88.1-10+deb12u15"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "7.88.1-10+deb12u15",
              "date": "2026-07-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.314665
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-14524",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-14524.html",
            "https://curl.se/docs/CVE-2025-14524.json",
            "https://hackerone.com/reports/3459417",
            "http://www.openwall.com/lists/oss-security/2026/01/07/4"
          ],
          "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-14524",
              "epss": 0.00611,
              "percentile": 0.45702,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-14524",
              "cwe": "CWE-601",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-14524",
            "versionConstraint": "< 7.88.1-10+deb12u15 (deb)"
          },
          "fix": {
            "suggestedVersion": "7.88.1-10+deb12u15"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-66033",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-66033",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs.",
        "cvss": [
          {
            "source": "disclosure@vulncheck.com",
            "type": "Secondary",
            "version": "4.0",
            "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "metrics": {
              "baseScore": 8.7
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-66033",
            "epss": 0.00386,
            "percentile": 0.31315,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-66033",
            "cwe": "CWE-125",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-66033",
            "cwe": "CWE-191",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.31266
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-66033",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-66033",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6",
            "https://github.com/libssh2/libssh2/pull/2401",
            "https://www.vulncheck.com/advisories/libssh2-integer-underflow-dos-via-aes-gcm-cipher-negotiation"
          ],
          "description": "libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs.",
          "cvss": [
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 8.7
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-66033",
              "epss": 0.00386,
              "percentile": 0.31315,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-66033",
              "cwe": "CWE-125",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-66033",
              "cwe": "CWE-191",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libssh2",
              "version": "1.10.0-3"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-66033",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8905b74027385650",
        "name": "libssh2-1",
        "version": "1.10.0-3+b1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssh2-1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssh2-1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12&upstream=libssh2%401.10.0-3",
        "upstreams": [
          {
            "name": "libssh2",
            "version": "1.10.0-3"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6637",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6637",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Stack buffer overflow in PostgreSQL module \"refint\" allows an unprivileged database user to execute arbitrary code as the operating system user running the database.  A distinct attack is possible if the application declares a user-controlled column as a \"refint\" cascade primary key and facilitates user-controlled updates to that column.  In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
        "cvss": [
          {
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.8,
              "exploitabilityScore": 2.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6637",
            "epss": 0.00378,
            "percentile": 0.30409,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6637",
            "cwe": "CWE-89",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-6637",
            "cwe": "CWE-121",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.18-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.18-0+deb12u1",
              "date": "2026-05-14",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6269-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6269-1"
          }
        ],
        "risk": 0.30807
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6637",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6637",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-6637/"
          ],
          "description": "Stack buffer overflow in PostgreSQL module \"refint\" allows an unprivileged database user to execute arbitrary code as the operating system user running the database.  A distinct attack is possible if the application declares a user-controlled column as a \"refint\" cascade primary key and facilitates user-controlled updates to that column.  In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
          "cvss": [
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6637",
              "epss": 0.00378,
              "percentile": 0.30409,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6637",
              "cwe": "CWE-89",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-6637",
              "cwe": "CWE-121",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6637",
            "versionConstraint": "< 15.18-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.18-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42767",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-42767",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42767",
            "epss": 0.00557,
            "percentile": 0.43127,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42767",
            "cwe": "CWE-476",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.30356500000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42767",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42767",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046",
            "https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774",
            "https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f",
            "https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873",
            "https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42767",
              "epss": 0.00557,
              "percentile": 0.43127,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42767",
              "cwe": "CWE-476",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42767",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8932",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-8932",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8932",
            "epss": 0.00396,
            "percentile": 0.32335,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-8932",
            "cwe": "NVD-CWE-Other",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.297
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8932",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8932",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-8932.html",
            "https://curl.se/docs/CVE-2026-8932.json",
            "https://hackerone.com/reports/3733910"
          ],
          "description": "libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8932",
              "epss": 0.00396,
              "percentile": 0.32335,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-8932",
              "cwe": "NVD-CWE-Other",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8932",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2018-20796",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2018-20796",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2018-20796",
            "epss": 0.05804,
            "percentile": 0.92352,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2018-20796",
            "cwe": "CWE-674",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.2902
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2018-20796",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2018-20796",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "http://www.securityfocus.com/bid/107160",
            "https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141",
            "https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html",
            "https://security.netapp.com/advisory/ntap-20190315-0002/",
            "https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"
          ],
          "description": "In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.0",
              "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 10,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2018-20796",
              "epss": 0.05804,
              "percentile": 0.92352,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2018-20796",
              "cwe": "CWE-674",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2018-20796",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4046",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-4046",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4046",
            "epss": 0.0038,
            "percentile": 0.30643,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4046",
            "cwe": "CWE-617",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "2.36-9+deb12u14"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "2.36-9+deb12u14",
              "date": "2026-05-17",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.28500000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4046",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4046",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=33980",
            "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4046",
              "epss": 0.0038,
              "percentile": 0.30643,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4046",
              "cwe": "CWE-617",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4046",
            "versionConstraint": "< 2.36-9+deb12u14 (deb)"
          },
          "fix": {
            "suggestedVersion": "2.36-9+deb12u14"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-0861",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-0861",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.  Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1<<62+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc.  Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.4,
              "exploitabilityScore": 2.6,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-0861",
            "epss": 0.00352,
            "percentile": 0.27875,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-0861",
            "cwe": "CWE-190",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "2.36-9+deb12u14"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "2.36-9+deb12u14",
              "date": "2026-05-17",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.27984000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-0861",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-0861",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=33796",
            "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0001",
            "http://www.openwall.com/lists/oss-security/2026/01/16/5"
          ],
          "description": "Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.\n\nNote that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1<<62+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc.\n\nTypically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.4,
                "exploitabilityScore": 2.6,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-0861",
              "epss": 0.00352,
              "percentile": 0.27875,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-0861",
              "cwe": "CWE-190",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-0861",
            "versionConstraint": "< 2.36-9+deb12u14 (deb)"
          },
          "fix": {
            "suggestedVersion": "2.36-9+deb12u14"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5928",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-5928",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5928",
            "epss": 0.00369,
            "percentile": 0.29528,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5928",
            "cwe": "CWE-127",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.27675
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5928",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5928",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=33998",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5928",
              "epss": 0.00369,
              "percentile": 0.29528,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5928",
              "cwe": "CWE-127",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5928",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6429",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6429",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 1.7,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6429",
            "epss": 0.00519,
            "percentile": 0.41113,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.267285
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6429",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-6429.html",
            "https://curl.se/docs/CVE-2026-6429.json",
            "https://hackerone.com/reports/3677759"
          ],
          "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6429",
              "epss": 0.00519,
              "percentile": 0.41113,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6429",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6475",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6475",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account.  It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries.  Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
        "cvss": [
          {
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 8.8,
              "exploitabilityScore": 2.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6475",
            "epss": 0.00324,
            "percentile": 0.24813,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6475",
            "cwe": "CWE-61",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.18-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.18-0+deb12u1",
              "date": "2026-05-14",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6269-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6269-1"
          }
        ],
        "risk": 0.26405999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6475",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6475",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-6475/"
          ],
          "description": "Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account.  It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries.  Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
          "cvss": [
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6475",
              "epss": 0.00324,
              "percentile": 0.24813,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6475",
              "cwe": "CWE-61",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6475",
            "versionConstraint": "< 15.18-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.18-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2015-3276",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2015-3276",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2015-3276",
            "epss": 0.05269,
            "percentile": 0.91709,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.26345
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2015-3276",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2015-3276",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "http://rhn.redhat.com/errata/RHSA-2015-2131.html",
            "http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html",
            "http://www.securitytracker.com/id/1034221",
            "https://bugzilla.redhat.com/show_bug.cgi?id=1238322"
          ],
          "description": "The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 10,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2015-3276",
              "epss": 0.05269,
              "percentile": 0.91709,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openldap",
              "version": "2.5.13+dfsg-5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2015-3276",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "919a44d8cbaa32e2",
        "name": "libldap-2.5-0",
        "version": "2.5.13+dfsg-5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12&upstream=openldap",
        "upstreams": [
          {
            "name": "openldap"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-22796",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-22796",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.  Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-22796",
            "epss": 0.00502,
            "percentile": 0.40059,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-22796",
            "cwe": "CWE-754",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.18-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.18-1~deb12u2",
              "date": "2026-01-27",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6113-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6113-1"
          }
        ],
        "risk": 0.25853
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-22796",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-22796",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4",
            "https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49",
            "https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12",
            "https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e",
            "https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2",
            "https://openssl-library.org/news/secadv/20260127.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an ASN1_TYPE union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\n\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the PKCS7_digest_from_attributes() function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\n\nThe function PKCS7_digest_from_attributes() accesses the message digest attribute\nvalue without validating its type. When the type is not V_ASN1_OCTET_STRING,\nthis results in accessing invalid memory through the ASN1_TYPE union, causing\na crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-22796",
              "epss": 0.00502,
              "percentile": 0.40059,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-22796",
              "cwe": "CWE-754",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-22796",
            "versionConstraint": "< 3.0.18-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.18-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42012",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-42012",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.",
        "cvss": [
          {
            "source": "secalert@redhat.com",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N",
            "metrics": {
              "baseScore": 7.1,
              "exploitabilityScore": 2.9,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42012",
            "epss": 0.00354,
            "percentile": 0.28016,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42012",
            "cwe": "CWE-295",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 0.25842
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42012",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42012",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-42012",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467441",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-7"
          ],
          "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N",
              "metrics": {
                "baseScore": 7.1,
                "exploitabilityScore": 2.9,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42012",
              "epss": 0.00354,
              "percentile": 0.28016,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42012",
              "cwe": "CWE-295",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42012",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-12064",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-12064",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-12064",
            "epss": 0.00339,
            "percentile": 0.26413,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-12064",
            "cwe": "CWE-295",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.25425
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-12064",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-12064",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-12064.html",
            "https://curl.se/docs/CVE-2026-12064.json",
            "https://hackerone.com/reports/3797526"
          ],
          "description": "When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-12064",
              "epss": 0.00339,
              "percentile": 0.26413,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-12064",
              "cwe": "CWE-295",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-12064",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4437",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-4437",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4437",
            "epss": 0.00325,
            "percentile": 0.24931,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4437",
            "cwe": "CWE-125",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "2.36-9+deb12u14"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "2.36-9+deb12u14",
              "date": "2026-05-17",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.24375
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4437",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4437",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34014",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4437",
              "epss": 0.00325,
              "percentile": 0.24931,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4437",
              "cwe": "CWE-125",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4437",
            "versionConstraint": "< 2.36-9+deb12u14 (deb)"
          },
          "fix": {
            "suggestedVersion": "2.36-9+deb12u14"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-66035",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-66035",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication.",
        "cvss": [
          {
            "source": "disclosure@vulncheck.com",
            "type": "Secondary",
            "version": "4.0",
            "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "metrics": {
              "baseScore": 7.7
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-66035",
            "epss": 0.0032,
            "percentile": 0.24409,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-66035",
            "cwe": "CWE-122",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.24320000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-66035",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-66035",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4",
            "https://github.com/libssh2/libssh2/pull/2198",
            "https://www.vulncheck.com/advisories/libssh2-heap-buffer-overflow-via-etm-cipher-negotiation"
          ],
          "description": "libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication.",
          "cvss": [
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 7.7
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 1.7,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-66035",
              "epss": 0.0032,
              "percentile": 0.24409,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-66035",
              "cwe": "CWE-122",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libssh2",
              "version": "1.10.0-3"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-66035",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8905b74027385650",
        "name": "libssh2-1",
        "version": "1.10.0-3+b1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssh2-1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssh2-1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12&upstream=libssh2%401.10.0-3",
        "upstreams": [
          {
            "name": "libssh2",
            "version": "1.10.0-3"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-7168",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-7168",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for `proxyA`, to `proxyB`.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-7168",
            "epss": 0.00471,
            "percentile": 0.38175,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-7168",
            "cwe": "CWE-294",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [
            "7.88.1-10+deb12u15"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "7.88.1-10+deb12u15",
              "date": "2026-07-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.242565
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-7168",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-7168.html",
            "https://curl.se/docs/CVE-2026-7168.json",
            "https://hackerone.com/reports/3697719",
            "http://www.openwall.com/lists/oss-security/2026/04/29/14"
          ],
          "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-7168",
              "epss": 0.00471,
              "percentile": 0.38175,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-7168",
              "cwe": "CWE-294",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-7168",
            "versionConstraint": "< 7.88.1-10+deb12u15 (deb)"
          },
          "fix": {
            "suggestedVersion": "7.88.1-10+deb12u15"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8286",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-8286",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "metrics": {
              "baseScore": 8.1,
              "exploitabilityScore": 2.9,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8286",
            "epss": 0.00309,
            "percentile": 0.23281,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-8286",
            "cwe": "CWE-295",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.24101999999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8286",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8286",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-8286.html",
            "https://curl.se/docs/CVE-2026-8286.json",
            "https://hackerone.com/reports/3718195"
          ],
          "description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 8.1,
                "exploitabilityScore": 2.9,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8286",
              "epss": 0.00309,
              "percentile": 0.23281,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-8286",
              "cwe": "CWE-295",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8286",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-10148",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-10148",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "curl's websocket code did not update the 32 bit mask pattern for each new  outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection.  A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-10148",
            "epss": 0.00466,
            "percentile": 0.37844,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [
            "7.88.1-10+deb12u15"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "7.88.1-10+deb12u15",
              "date": "2026-07-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.23998999999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-10148",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-10148",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-10148.html",
            "https://curl.se/docs/CVE-2025-10148.json",
            "https://hackerone.com/reports/3330839",
            "http://www.openwall.com/lists/oss-security/2025/09/10/2",
            "http://www.openwall.com/lists/oss-security/2025/09/10/3",
            "http://www.openwall.com/lists/oss-security/2025/09/10/4"
          ],
          "description": "curl's websocket code did not update the 32 bit mask pattern for each new\n outgoing frame as the specification says. Instead it used a fixed mask that\npersisted and was used throughout the entire connection.\n\nA predictable mask pattern allows for a malicious server to induce traffic\nbetween the two communicating parties that could be interpreted by an involved\nproxy (configured or transparent) as genuine, real, HTTP traffic with content\nand thereby poison its cache. That cached poisoned content could then be\nserved to all users of that proxy.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-10148",
              "epss": 0.00466,
              "percentile": 0.37844,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-10148",
            "versionConstraint": "< 7.88.1-10+deb12u15 (deb)"
          },
          "fix": {
            "suggestedVersion": "7.88.1-10+deb12u15"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5545",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-5545",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.3,
              "impactScore": 4.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5545",
            "epss": 0.00414,
            "percentile": 0.33937,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5545",
            "cwe": "CWE-613",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.23804999999999993
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5545",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-5545.html",
            "https://curl.se/docs/CVE-2026-5545.json",
            "https://hackerone.com/reports/3642555"
          ],
          "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.3,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.3,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5545",
              "epss": 0.00414,
              "percentile": 0.33937,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5545",
              "cwe": "CWE-613",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5545",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-66032",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-66032",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.",
        "cvss": [
          {
            "source": "disclosure@vulncheck.com",
            "type": "Secondary",
            "version": "4.0",
            "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "metrics": {
              "baseScore": 8.7
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-66032",
            "epss": 0.00288,
            "percentile": 0.21058,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-66032",
            "cwe": "CWE-415",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.23328
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-66032",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-66032",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0",
            "https://github.com/libssh2/libssh2/pull/2180",
            "https://www.vulncheck.com/advisories/libssh2-double-free-heap-corruption-via-sftp-open"
          ],
          "description": "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.",
          "cvss": [
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 8.7
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-66032",
              "epss": 0.00288,
              "percentile": 0.21058,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-66032",
              "cwe": "CWE-415",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libssh2",
              "version": "1.10.0-3"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-66032",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8905b74027385650",
        "name": "libssh2-1",
        "version": "1.10.0-3+b1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssh2-1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssh2-1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12&upstream=libssh2%401.10.0-3",
        "upstreams": [
          {
            "name": "libssh2",
            "version": "1.10.0-3"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-34743",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-34743",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-34743",
            "epss": 0.0045,
            "percentile": 0.36788,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-34743",
            "cwe": "CWE-122",
            "source": "security-advisories@github.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "5.4.1-1+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "5.4.1-1+deb12u1",
              "date": "2026-07-14",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.23174999999999996
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-34743",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-34743",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87",
            "https://github.com/tukaani-project/xz/releases/tag/v5.8.3",
            "https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv",
            "http://www.openwall.com/lists/oss-security/2026/03/31/13",
            "https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"
          ],
          "description": "XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "security-advisories@github.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 1.7
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-34743",
              "epss": 0.0045,
              "percentile": 0.36788,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-34743",
              "cwe": "CWE-122",
              "source": "security-advisories@github.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "xz-utils",
              "version": "5.4.1-1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-34743",
            "versionConstraint": "< 5.4.1-1+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "5.4.1-1+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "472c1368193da0b1",
        "name": "liblzma5",
        "version": "5.4.1-1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/liblzma5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/liblzma5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:liblzma5:liblzma5:5.4.1-1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/liblzma5@5.4.1-1?arch=amd64&distro=debian-12&upstream=xz-utils",
        "upstreams": [
          {
            "name": "xz-utils"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-31789",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-31789",
        "namespace": "debian:distro:debian:12",
        "severity": "Critical",
        "urls": [],
        "description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 9.8,
              "exploitabilityScore": 3.9,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-31789",
            "epss": 0.00243,
            "percentile": 0.15665,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-31789",
            "cwe": "CWE-787",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.19-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.19-1~deb12u2",
              "date": "2026-04-07",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6201-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6201-1"
          }
        ],
        "risk": 0.22842
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-31789",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-31789",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde",
            "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf",
            "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49",
            "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9",
            "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521",
            "https://openssl-library.org/news/secadv/20260407.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H",
              "metrics": {
                "baseScore": 5.8,
                "exploitabilityScore": 1.1,
                "impactScore": 4.8
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-31789",
              "epss": 0.00243,
              "percentile": 0.15665,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-31789",
              "cwe": "CWE-787",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-31789",
            "versionConstraint": "< 3.0.19-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.19-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6276",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6276",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 7.5,
              "exploitabilityScore": 3.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6276",
            "epss": 0.00295,
            "percentile": 0.21729,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6276",
            "cwe": "CWE-319",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.22125
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6276",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-6276.html",
            "https://curl.se/docs/CVE-2026-6276.json",
            "https://hackerone.com/reports/3671818",
            "http://www.openwall.com/lists/oss-security/2026/04/29/13"
          ],
          "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6276",
              "epss": 0.00295,
              "percentile": 0.21729,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6276",
              "cwe": "CWE-319",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6276",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6238",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6238",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6238",
            "epss": 0.00358,
            "percentile": 0.28449,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6238",
            "cwe": "CWE-126",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.20584999999999995
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6238",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6238",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34069",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6238",
              "epss": 0.00358,
              "percentile": 0.28449,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6238",
              "cwe": "CWE-126",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6238",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-12978",
        "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-12978",
        "namespace": "nvd:cpe",
        "severity": "Medium",
        "urls": [
          "https://fluentbit.io/announcements/v4.1.0/"
        ],
        "description": "Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows crafted inputs where a tag prefix is incorrectly treated as a full match. A remote attacker with authenticated or exposed access to these input endpoints can exploit this behavior to manipulate tags and redirect records to unintended destinations. This compromises the authenticity of ingested logs and can allow injection of forged data, alert flooding and routing manipulation.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "metrics": {
              "baseScore": 5.4,
              "exploitabilityScore": 2.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-12978",
            "epss": 0.00384,
            "percentile": 0.31093,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": ""
        },
        "advisories": [],
        "risk": 0.19968
      },
      "relatedVulnerabilities": [],
      "matchDetails": [
        {
          "type": "cpe-match",
          "matcher": "stock-matcher",
          "searchedBy": {
            "namespace": "nvd:cpe",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
            ],
            "package": {
              "name": "fluent-bit",
              "version": "4.1.0"
            }
          },
          "found": {
            "vulnerabilityID": "CVE-2025-12978",
            "versionConstraint": "= 4.1.0 (unknown)",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*"
            ]
          }
        }
      ],
      "artifact": {
        "id": "c9f8017f4b3fb0ab",
        "name": "fluent-bit",
        "version": "4.1.0",
        "type": "binary",
        "locations": [
          {
            "path": "/fluent-bit/bin/fluent-bit",
            "layerID": "sha256:0f3590c76e91ee02acf305bdcff2f981bc9f783070524382028f071e8da36d86",
            "accessPath": "/fluent-bit/bin/fluent-bit",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:github/fluent/fluent-bit@4.1.0",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-66034",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-66034",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.",
        "cvss": [
          {
            "source": "disclosure@vulncheck.com",
            "type": "Secondary",
            "version": "4.0",
            "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "metrics": {
              "baseScore": 7.7
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-66034",
            "epss": 0.00254,
            "percentile": 0.16991,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-66034",
            "cwe": "CWE-125",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-66034",
            "cwe": "CWE-908",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.19304000000000002
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-66034",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-66034",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9",
            "https://github.com/libssh2/libssh2/pull/2202",
            "https://www.vulncheck.com/advisories/libssh2-heap-out-of-bounds-read-via-publickey-subsystem"
          ],
          "description": "libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.",
          "cvss": [
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 7.7
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 1.7,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-66034",
              "epss": 0.00254,
              "percentile": 0.16991,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-66034",
              "cwe": "CWE-125",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-66034",
              "cwe": "CWE-908",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libssh2",
              "version": "1.10.0-3"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-66034",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8905b74027385650",
        "name": "libssh2-1",
        "version": "1.10.0-3+b1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssh2-1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssh2-1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12&upstream=libssh2%401.10.0-3",
        "upstreams": [
          {
            "name": "libssh2",
            "version": "1.10.0-3"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-8458",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-8458",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-8458",
            "epss": 0.00315,
            "percentile": 0.23868,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.18112499999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-8458",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-8458",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-8458.html",
            "https://curl.se/docs/CVE-2026-8458.json",
            "https://hackerone.com/reports/3721183"
          ],
          "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n'services'.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-8458",
              "epss": 0.00315,
              "percentile": 0.23868,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-8458",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-12818",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-12818",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes.  This results in a segmentation fault for the application using libpq.  Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.",
        "cvss": [
          {
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-12818",
            "epss": 0.00332,
            "percentile": 0.25706,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-12818",
            "cwe": "CWE-190",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.15-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.15-0+deb12u1",
              "date": "2026-01-19",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.18094000000000002
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-12818",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-12818",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2025-12818/"
          ],
          "description": "Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes.  This results in a segmentation fault for the application using libpq.  Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.",
          "cvss": [
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-12818",
              "epss": 0.00332,
              "percentile": 0.25706,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-12818",
              "cwe": "CWE-190",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-12818",
            "versionConstraint": "< 15.15-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.15-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4873",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-4873",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "metrics": {
              "baseScore": 5.9,
              "exploitabilityScore": 2.3,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4873",
            "epss": 0.00329,
            "percentile": 0.2535,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4873",
            "cwe": "CWE-295",
            "source": "nvd@nist.gov",
            "type": "Primary"
          },
          {
            "cve": "CVE-2026-4873",
            "cwe": "CWE-319",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.179305
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4873",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-4873.html",
            "https://curl.se/docs/CVE-2026-4873.json",
            "https://hackerone.com/reports/3621851",
            "http://www.openwall.com/lists/oss-security/2026/04/29/7"
          ],
          "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4873",
              "epss": 0.00329,
              "percentile": 0.2535,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4873",
              "cwe": "CWE-295",
              "source": "nvd@nist.gov",
              "type": "Primary"
            },
            {
              "cve": "CVE-2026-4873",
              "cwe": "CWE-319",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4873",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-45446",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-45446",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.  Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers.  AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully.  In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value.  When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key.  AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2.  No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 4.8,
              "exploitabilityScore": 2.3,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-45446",
            "epss": 0.00363,
            "percentile": 0.28938,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-45446",
            "cwe": "CWE-325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.20-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.20-1~deb12u2",
              "date": "2026-06-09",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6335-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6335-1"
          }
        ],
        "risk": 0.17787
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-45446",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-45446",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/25b32cd9d41d2bc01b6abc425bb4baf2c2236fdc",
            "https://github.com/openssl/openssl/commit/71e2a5d263518cf5866043bd60ee4994d59e53a3",
            "https://github.com/openssl/openssl/commit/7fe3f33a3b3a4c487aa4dcdbc87057f66ffd2b85",
            "https://github.com/openssl/openssl/commit/daca0f48e4a69a2892a62262bad59e62a8a76598",
            "https://github.com/openssl/openssl/commit/eec5e9bf0d867333b8495e456f5235d225798a68",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV\n(RFC 8452) mishandle the authentication of AAD (Additional Authenticated\nData) with an empty ciphertext allowing a forgery of such messages.\n\nImpact summary: An attacker can forge empty messages with arbitrary AAD\nto the victim's application using these ciphers.\n\nAES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD\nmodes: they accept a key, nonce, optional AAD (bytes that are authenticated\nbut not encrypted), and plaintext, and produces ciphertext plus a 16-byte\ntag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only\nif the tag is verified succesfully.\n\nIn OpenSSL's provider implementation of these ciphers, the expected tag is\ncomputed only when decryption function is invoked with non-empty data.\nIf the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without\ninvocation of the ciphertext update, which can happen when the received\nciphertext length is zero, the tag is never recalculated and still holds its\nall-zeros value.\n\nWhen AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty\nciphertext, and all-zeros tag passes authentication under any key they do not\nknow, single-shot. When AES-SIV is used, for mounting the attack it's\nnecessary for the application to reuse the decryption context without\nresetting the key.\n\nAES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since\nOpenSSL 3.2.\n\nNo protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support\neither AES-GCM-SIV or AES-SIV. To mount an attack, the applications must\nimplement their own protocol and use the EVP interface. Also they must skip the\nciphertext update when a message with an empty ciphertext arrives.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as these algorithms are not FIPS approved and the affected code is\noutside the OpenSSL FIPS module boundary.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 4.8,
                "exploitabilityScore": 2.3,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-45446",
              "epss": 0.00363,
              "percentile": 0.28938,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-45446",
              "cwe": "CWE-325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-45446",
            "versionConstraint": "< 3.0.20-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.20-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5435",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-5435",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "metrics": {
              "baseScore": 7.3,
              "exploitabilityScore": 3.9,
              "impactScore": 3.4
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5435",
            "epss": 0.00237,
            "percentile": 0.1487,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5435",
            "cwe": "CWE-787",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.17538
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5435",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5435",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34033",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 7.3,
                "exploitabilityScore": 3.9,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5435",
              "epss": 0.00237,
              "percentile": 0.1487,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5435",
              "cwe": "CWE-787",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5435",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-3784",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-3784",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 3.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-3784",
            "epss": 0.00302,
            "percentile": 0.22457,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-3784",
            "cwe": "CWE-305",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "7.88.1-10+deb12u15"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "7.88.1-10+deb12u15",
              "date": "2026-07-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.17365
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-3784",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-3784.html",
            "https://curl.se/docs/CVE-2026-3784.json",
            "https://hackerone.com/reports/3584903",
            "http://www.openwall.com/lists/oss-security/2026/03/11/3",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
          ],
          "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 3.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-3784",
              "epss": 0.00302,
              "percentile": 0.22457,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-3784",
              "cwe": "CWE-305",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-3784",
            "versionConstraint": "< 7.88.1-10+deb12u15 (deb)"
          },
          "fix": {
            "suggestedVersion": "7.88.1-10+deb12u15"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-3783",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-3783",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances.  If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `default` keywords, curl would pass on the bearer token set for the first host also to the second one.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 5.3,
              "exploitabilityScore": 3.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-3783",
            "epss": 0.00333,
            "percentile": 0.25811,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-3783",
            "cwe": "CWE-522",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "7.88.1-10+deb12u15"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "7.88.1-10+deb12u15",
              "date": "2026-07-12",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.171495
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-3783",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-3783",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-3783.html",
            "https://curl.se/docs/CVE-2026-3783.json",
            "https://hackerone.com/reports/3583983",
            "http://www.openwall.com/lists/oss-security/2026/03/11/2"
          ],
          "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-3783",
              "epss": 0.00333,
              "percentile": 0.25811,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-3783",
              "cwe": "CWE-522",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-3783",
            "versionConstraint": "< 7.88.1-10+deb12u15 (deb)"
          },
          "fix": {
            "suggestedVersion": "7.88.1-10+deb12u15"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4438",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-4438",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 5.4,
              "exploitabilityScore": 2.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4438",
            "epss": 0.00316,
            "percentile": 0.23977,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4438",
            "cwe": "CWE-20",
            "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-4438",
            "cwe": "CWE-88",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "2.36-9+deb12u14"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "2.36-9+deb12u14",
              "date": "2026-05-17",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.16432
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4438",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4438",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=34015",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 5.4,
                "exploitabilityScore": 2.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4438",
              "epss": 0.00316,
              "percentile": 0.23977,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4438",
              "cwe": "CWE-20",
              "source": "3ff69d7a-14f2-4f67-a097-88dee7810d18",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-4438",
              "cwe": "CWE-88",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4438",
            "versionConstraint": "< 2.36-9+deb12u14 (deb)"
          },
          "fix": {
            "suggestedVersion": "2.36-9+deb12u14"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2019-1010022",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2019-1010022",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2019-1010022",
            "epss": 0.03249,
            "percentile": 0.87037,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2019-1010022",
            "cwe": "CWE-119",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.16245
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2019-1010022",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2019-1010022",
          "namespace": "nvd:cpe",
          "severity": "Critical",
          "urls": [
            "https://security-tracker.debian.org/tracker/CVE-2019-1010022",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=22850",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3",
            "https://ubuntu.com/security/CVE-2019-1010022"
          ],
          "description": "GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.0",
              "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 9.8,
                "exploitabilityScore": 3.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 10,
                "impactScore": 6.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2019-1010022",
              "epss": 0.03249,
              "percentile": 0.87037,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2019-1010022",
              "cwe": "CWE-119",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2019-1010022",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2019-1010024",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2019-1010024",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2019-1010024",
            "epss": 0.0322,
            "percentile": 0.86914,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2019-1010024",
            "cwe": "CWE-200",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.161
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2019-1010024",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2019-1010024",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "http://www.securityfocus.com/bid/109162",
            "https://security-tracker.debian.org/tracker/CVE-2019-1010024",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=22852",
            "https://support.f5.com/csp/article/K06046097",
            "https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS",
            "https://ubuntu.com/security/CVE-2019-1010024"
          ],
          "description": "GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.0",
              "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 10,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2019-1010024",
              "epss": 0.0322,
              "percentile": 0.86914,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2019-1010024",
              "cwe": "CWE-200",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2019-1010024",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2019-1010023",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2019-1010023",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2019-1010023",
            "epss": 0.03069,
            "percentile": 0.86271,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.15345
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2019-1010023",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2019-1010023",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "http://www.securityfocus.com/bid/109167",
            "https://security-tracker.debian.org/tracker/CVE-2019-1010023",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=22851",
            "https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS",
            "https://ubuntu.com/security/CVE-2019-1010023"
          ],
          "description": "GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.0",
              "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 8.8,
                "exploitabilityScore": 2.9,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
              "metrics": {
                "baseScore": 6.8,
                "exploitabilityScore": 8.6,
                "impactScore": 6.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 5.4,
                "exploitabilityScore": 2.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2019-1010023",
              "epss": 0.03069,
              "percentile": 0.86271,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2019-1010023",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42770",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-42770",
        "namespace": "debian:distro:debian:12",
        "severity": "Low",
        "urls": [],
        "description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership.  Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts.  When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared.  A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack).  The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42770",
            "epss": 0.00455,
            "percentile": 0.37149,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42770",
            "cwe": "CWE-325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.20-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.20-1~deb12u2",
              "date": "2026-06-09",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6335-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6335-1"
          }
        ],
        "risk": 0.152425
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42770",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42770",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02",
            "https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb",
            "https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c",
            "https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2",
            "https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070",
            "https://openssl-library.org/news/secadv/20260609.txt"
          ],
          "description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42770",
              "epss": 0.00455,
              "percentile": 0.37149,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42770",
              "cwe": "CWE-325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42770",
            "versionConstraint": "< 3.0.20-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.20-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-4878",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-4878",
        "namespace": "debian:distro:debian:12",
        "severity": "High",
        "urls": [],
        "description": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "metrics": {
              "baseScore": 7,
              "exploitabilityScore": 1.1,
              "impactScore": 5.9
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-4878",
            "epss": 0.00206,
            "percentile": 0.10855,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-4878",
            "cwe": "CWE-367",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-4878",
            "cwe": "CWE-367",
            "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1:2.66-4+deb12u3"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1:2.66-4+deb12u3",
              "date": "2026-05-17",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.14935
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-4878",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-4878",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:12423",
            "https://access.redhat.com/errata/RHSA-2026:12441",
            "https://access.redhat.com/errata/RHSA-2026:13285",
            "https://access.redhat.com/errata/RHSA-2026:14162",
            "https://access.redhat.com/errata/RHSA-2026:14937",
            "https://access.redhat.com/errata/RHSA-2026:19130",
            "https://access.redhat.com/errata/RHSA-2026:19346",
            "https://access.redhat.com/errata/RHSA-2026:19456",
            "https://access.redhat.com/errata/RHSA-2026:19458",
            "https://access.redhat.com/errata/RHSA-2026:20595",
            "https://access.redhat.com/errata/RHSA-2026:21254",
            "https://access.redhat.com/errata/RHSA-2026:21275",
            "https://access.redhat.com/errata/RHSA-2026:22634",
            "https://access.redhat.com/errata/RHSA-2026:22957",
            "https://access.redhat.com/errata/RHSA-2026:23233",
            "https://access.redhat.com/errata/RHSA-2026:23245",
            "https://access.redhat.com/errata/RHSA-2026:24346",
            "https://access.redhat.com/errata/RHSA-2026:25044",
            "https://access.redhat.com/errata/RHSA-2026:25096",
            "https://access.redhat.com/errata/RHSA-2026:25181",
            "https://access.redhat.com/errata/RHSA-2026:26542",
            "https://access.redhat.com/errata/RHSA-2026:27998",
            "https://access.redhat.com/errata/RHSA-2026:28887",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30078",
            "https://access.redhat.com/errata/RHSA-2026:30087",
            "https://access.redhat.com/errata/RHSA-2026:30088",
            "https://access.redhat.com/errata/RHSA-2026:30089",
            "https://access.redhat.com/errata/RHSA-2026:34098",
            "https://access.redhat.com/errata/RHSA-2026:39981",
            "https://access.redhat.com/errata/RHSA-2026:7473",
            "https://access.redhat.com/security/cve/CVE-2026-4878",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2447554",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2451615",
            "http://www.openwall.com/lists/oss-security/2026/04/07/14",
            "http://www.openwall.com/lists/oss-security/2026/04/07/4",
            "http://www.openwall.com/lists/oss-security/2026/04/08/9",
            "http://www.openwall.com/lists/oss-security/2026/04/09/5",
            "http://www.openwall.com/lists/oss-security/2026/04/09/6",
            "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4878.json"
          ],
          "description": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 7,
                "exploitabilityScore": 1.1,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 6.7,
                "exploitabilityScore": 0.8,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            },
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
              "metrics": {
                "baseScore": 6.7,
                "exploitabilityScore": 0.8,
                "impactScore": 5.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-4878",
              "epss": 0.00206,
              "percentile": 0.10855,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-4878",
              "cwe": "CWE-367",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-4878",
              "cwe": "CWE-367",
              "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libcap2",
              "version": "1:2.66-4+deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-4878",
            "versionConstraint": "< 1:2.66-4+deb12u3 (deb)"
          },
          "fix": {
            "suggestedVersion": "1:2.66-4+deb12u3"
          }
        }
      ],
      "artifact": {
        "id": "a55e64e0eb914b2a",
        "name": "libcap2",
        "version": "1:2.66-4+deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcap2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcap2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcap2:libcap2:1\\:2.66-4\\+deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcap2@1%3A2.66-4%2Bdeb12u2?arch=amd64&distro=debian-12",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-1965",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-1965",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work.  An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it just sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1...  The set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.  Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API).",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "metrics": {
              "baseScore": 6.5,
              "exploitabilityScore": 2.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-1965",
            "epss": 0.00259,
            "percentile": 0.17569,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-1965",
            "cwe": "CWE-305",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.148925
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-1965",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-1965",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2026-1965.html",
            "https://curl.se/docs/CVE-2026-1965.json"
          ],
          "description": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 6.5,
                "exploitabilityScore": 2.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-1965",
              "epss": 0.00259,
              "percentile": 0.17569,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-1965",
              "cwe": "CWE-305",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-1965",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2010-4756",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2010-4756",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2010-4756",
            "epss": 0.02633,
            "percentile": 0.83969,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2010-4756",
            "cwe": "CWE-399",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.13165
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2010-4756",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2010-4756",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "http://cxib.net/stuff/glob-0day.c",
            "http://securityreason.com/achievement_securityalert/89",
            "http://securityreason.com/exploitalert/9223",
            "https://bugzilla.redhat.com/show_bug.cgi?id=681681",
            "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756",
            "https://security.netapp.com/advisory/ntap-20241108-0002/"
          ],
          "description": "The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 4,
                "exploitabilityScore": 8,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2010-4756",
              "epss": 0.02633,
              "percentile": 0.83969,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2010-4756",
              "cwe": "CWE-399",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2010-4756",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-2003",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-2003",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Improper validation of type \"oidvector\" in PostgreSQL allows a database user to disclose a few bytes of server memory.  We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.",
        "cvss": [
          {
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 4.3,
              "exploitabilityScore": 2.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-2003",
            "epss": 0.00281,
            "percentile": 0.20334,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-2003",
            "cwe": "CWE-1287",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.16-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.16-0+deb12u1",
              "date": "2026-02-12",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6132-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6132-1"
          }
        ],
        "risk": 0.130665
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-2003",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-2003",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-2003/"
          ],
          "description": "Improper validation of type \"oidvector\" in PostgreSQL allows a database user to disclose a few bytes of server memory.  We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.",
          "cvss": [
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 2.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-2003",
              "epss": 0.00281,
              "percentile": 0.20334,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-2003",
              "cwe": "CWE-1287",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-2003",
            "versionConstraint": "< 15.16-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.16-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-5419",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-5419",
        "namespace": "debian:distro:debian:12",
        "severity": "Low",
        "urls": [],
        "description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.",
        "cvss": [
          {
            "source": "secalert@redhat.com",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 3.7,
              "exploitabilityScore": 2.3,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-5419",
            "epss": 0.00379,
            "percentile": 0.30598,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-5419",
            "cwe": "CWE-208",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 0.12696499999999997
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-5419",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-5419",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/security/cve/CVE-2026-5419",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467686",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13"
          ],
          "description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 3.7,
                "exploitabilityScore": 2.3,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-5419",
              "epss": 0.00379,
              "percentile": 0.30598,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-5419",
              "cwe": "CWE-208",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-5419",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2020-15719",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2020-15719",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2020-15719",
            "epss": 0.02515,
            "percentile": 0.83169,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2020-15719",
            "cwe": "CWE-295",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.12575
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2020-15719",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2020-15719",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00033.html",
            "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00059.html",
            "https://access.redhat.com/errata/RHBA-2019:3674",
            "https://bugs.openldap.org/show_bug.cgi?id=9266",
            "https://bugzilla.redhat.com/show_bug.cgi?id=1740070",
            "https://kc.mcafee.com/corporate/index?page=content&id=SB10365",
            "https://www.oracle.com/security-alerts/cpuapr2022.html"
          ],
          "description": "libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 4.2,
                "exploitabilityScore": 1.7,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:N",
              "metrics": {
                "baseScore": 4,
                "exploitabilityScore": 5,
                "impactScore": 5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2020-15719",
              "epss": 0.02515,
              "percentile": 0.83169,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2020-15719",
              "cwe": "CWE-295",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openldap",
              "version": "2.5.13+dfsg-5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2020-15719",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "919a44d8cbaa32e2",
        "name": "libldap-2.5-0",
        "version": "2.5.13+dfsg-5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12&upstream=openldap",
        "upstreams": [
          {
            "name": "openldap"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2019-9192",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2019-9192",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2019-9192",
            "epss": 0.02447,
            "percentile": 0.8268,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2019-9192",
            "cwe": "CWE-674",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.12235
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2019-9192",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2019-9192",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://sourceware.org/bugzilla/show_bug.cgi?id=24269",
            "https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"
          ],
          "description": "In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.0",
              "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 10,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2019-9192",
              "epss": 0.02447,
              "percentile": 0.8268,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2019-9192",
              "cwe": "CWE-674",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2019-9192",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-27171",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-27171",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 1.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-27171",
            "epss": 0.00218,
            "percentile": 0.1244,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-27171",
            "cwe": "CWE-1284",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.11445000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-27171",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-27171",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/",
            "https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf",
            "https://github.com/madler/zlib/issues/904",
            "https://github.com/madler/zlib/releases/tag/v1.3.2",
            "https://ostif.org/zlib-audit-complete/"
          ],
          "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-27171",
              "epss": 0.00218,
              "percentile": 0.1244,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-27171",
              "cwe": "CWE-1284",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "zlib",
              "version": "1:1.2.13.dfsg-1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-27171",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "ca40227a4415e447",
        "name": "zlib1g",
        "version": "1:1.2.13.dfsg-1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/zlib1g",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/zlib1g",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/zlib1g@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12&upstream=zlib",
        "upstreams": [
          {
            "name": "zlib"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2019-1010025",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2019-1010025",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2019-1010025",
            "epss": 0.02286,
            "percentile": 0.81392,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2019-1010025",
            "cwe": "CWE-330",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.11429999999999998
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2019-1010025",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2019-1010025",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://security-tracker.debian.org/tracker/CVE-2019-1010025",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=22853",
            "https://support.f5.com/csp/article/K06046097",
            "https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS",
            "https://ubuntu.com/security/CVE-2019-1010025"
          ],
          "description": "GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.0",
              "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 10,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2019-1010025",
              "epss": 0.02286,
              "percentile": 0.81392,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2019-1010025",
              "cwe": "CWE-330",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "glibc",
              "version": "2.36-9+deb12u13"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2019-1010025",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-58055",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-58055",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
        "cvss": [
          {
            "source": "disclosure@vulncheck.com",
            "type": "Secondary",
            "version": "4.0",
            "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "metrics": {
              "baseScore": 6.3
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-58055",
            "epss": 0.00202,
            "percentile": 0.10438,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-58055",
            "cwe": "CWE-444",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.11413000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-58055",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-58055",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc",
            "https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e",
            "https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"
          ],
          "description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
          "cvss": [
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 6.3
              },
              "vendorMetadata": {}
            },
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 5.4,
                "exploitabilityScore": 2.3,
                "impactScore": 2.8
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-58055",
              "epss": 0.00202,
              "percentile": 0.10438,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-58055",
              "cwe": "CWE-444",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "nghttp2",
              "version": "1.52.0-1+deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-58055",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7fba61587556f31d",
        "name": "libnghttp2-14",
        "version": "1.52.0-1+deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libnghttp2-14",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libnghttp2-14",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2:libnghttp2-14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2:libnghttp2_14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libnghttp2-14@1.52.0-1%2Bdeb12u2?arch=amd64&distro=debian-12&upstream=nghttp2",
        "upstreams": [
          {
            "name": "nghttp2"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-41989",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-41989",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.",
        "cvss": [
          {
            "source": "cve@mitre.org",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "metrics": {
              "baseScore": 6.7,
              "exploitabilityScore": 1.5,
              "impactScore": 5.2
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-41989",
            "epss": 0.00182,
            "percentile": 0.08137,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-41989",
            "cwe": "CWE-787",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "1.10.1-3+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "1.10.1-3+deb12u1",
              "date": "2026-05-22",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6294-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6294-1"
          }
        ],
        "risk": 0.10647000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-41989",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-41989",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://dev.gnupg.org/T8211",
            "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html",
            "https://www.openwall.com/lists/oss-security/2026/04/21/1",
            "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
            "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
          ],
          "description": "Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.",
          "cvss": [
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
              "metrics": {
                "baseScore": 6.7,
                "exploitabilityScore": 1.5,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-41989",
              "epss": 0.00182,
              "percentile": 0.08137,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-41989",
              "cwe": "CWE-787",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libgcrypt20",
              "version": "1.10.1-3"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-41989",
            "versionConstraint": "< 1.10.1-3+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "1.10.1-3+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "aa143951e2980797",
        "name": "libgcrypt20",
        "version": "1.10.1-3",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgcrypt20",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgcrypt20",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgcrypt20:libgcrypt20:1.10.1-3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgcrypt20@1.10.1-3?arch=amd64&distro=debian-12",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2018-5709",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2018-5709",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2018-5709",
            "epss": 0.02067,
            "percentile": 0.7943,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2018-5709",
            "cwe": "CWE-190",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.10335000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2018-5709",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2018-5709",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow",
            "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"
          ],
          "description": "An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.0",
              "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 10,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2018-5709",
              "epss": 0.02067,
              "percentile": 0.7943,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2018-5709",
              "cwe": "CWE-190",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2018-5709",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "c8948b00cda8062b",
        "name": "libgssapi-krb5-2",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2018-5709",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2018-5709",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2018-5709",
            "epss": 0.02067,
            "percentile": 0.7943,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2018-5709",
            "cwe": "CWE-190",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.10335000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2018-5709",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2018-5709",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow",
            "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"
          ],
          "description": "An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.0",
              "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 10,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2018-5709",
              "epss": 0.02067,
              "percentile": 0.7943,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2018-5709",
              "cwe": "CWE-190",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2018-5709",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8f3a478cb18888b8",
        "name": "libk5crypto3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libk5crypto3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libk5crypto3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2018-5709",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2018-5709",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2018-5709",
            "epss": 0.02067,
            "percentile": 0.7943,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2018-5709",
            "cwe": "CWE-190",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.10335000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2018-5709",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2018-5709",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow",
            "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"
          ],
          "description": "An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.0",
              "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 10,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2018-5709",
              "epss": 0.02067,
              "percentile": 0.7943,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2018-5709",
              "cwe": "CWE-190",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2018-5709",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "575c8aeb7addaf05",
        "name": "libkrb5-3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5-3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5-3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2018-5709",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2018-5709",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2018-5709",
            "epss": 0.02067,
            "percentile": 0.7943,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2018-5709",
            "cwe": "CWE-190",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.10335000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2018-5709",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2018-5709",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow",
            "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"
          ],
          "description": "An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.0",
              "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 10,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2018-5709",
              "epss": 0.02067,
              "percentile": 0.7943,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2018-5709",
              "cwe": "CWE-190",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2018-5709",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "f17cb326c34696aa",
        "name": "libkrb5support0",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5support0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5support0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-29478",
        "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-29478",
        "namespace": "nvd:cpe",
        "severity": "Medium",
        "urls": [
          "https://github.com/lmarch2/poc/blob/main/fluent-bit/fluent-bit.md"
        ],
        "description": "An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 1.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-29478",
            "epss": 0.0019,
            "percentile": 0.0896,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-29478",
            "cwe": "CWE-400",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": ""
        },
        "advisories": [],
        "risk": 0.09975
      },
      "relatedVulnerabilities": [],
      "matchDetails": [
        {
          "type": "cpe-match",
          "matcher": "stock-matcher",
          "searchedBy": {
            "namespace": "nvd:cpe",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
            ],
            "package": {
              "name": "fluent-bit",
              "version": "4.1.0"
            }
          },
          "found": {
            "vulnerabilityID": "CVE-2025-29478",
            "versionConstraint": "none (unknown)",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*"
            ]
          }
        }
      ],
      "artifact": {
        "id": "c9f8017f4b3fb0ab",
        "name": "fluent-bit",
        "version": "4.1.0",
        "type": "binary",
        "locations": [
          {
            "path": "/fluent-bit/bin/fluent-bit",
            "layerID": "sha256:0f3590c76e91ee02acf305bdcff2f981bc9f783070524382028f071e8da36d86",
            "accessPath": "/fluent-bit/bin/fluent-bit",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:github/fluent/fluent-bit@4.1.0",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6474",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6474",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
        "cvss": [
          {
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "metrics": {
              "baseScore": 4.3,
              "exploitabilityScore": 2.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6474",
            "epss": 0.00214,
            "percentile": 0.11871,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6474",
            "cwe": "CWE-134",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.18-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.18-0+deb12u1",
              "date": "2026-05-14",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6269-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6269-1"
          }
        ],
        "risk": 0.09950999999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6474",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6474",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-6474/"
          ],
          "description": "Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
          "cvss": [
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 2.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6474",
              "epss": 0.00214,
              "percentile": 0.11871,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6474",
              "cwe": "CWE-134",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6474",
            "versionConstraint": "< 15.18-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.18-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-9820",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-9820",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.",
        "cvss": [
          {
            "source": "secalert@redhat.com",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 4,
              "exploitabilityScore": 2.6,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-9820",
            "epss": 0.00203,
            "percentile": 0.10523,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-9820",
            "cwe": "CWE-121",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u6"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u6",
              "date": "2026-02-27",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.09135
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-9820",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-9820",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13812",
            "https://access.redhat.com/errata/RHSA-2026:3477",
            "https://access.redhat.com/errata/RHSA-2026:4188",
            "https://access.redhat.com/errata/RHSA-2026:4655",
            "https://access.redhat.com/errata/RHSA-2026:4943",
            "https://access.redhat.com/errata/RHSA-2026:5585",
            "https://access.redhat.com/errata/RHSA-2026:5606",
            "https://access.redhat.com/errata/RHSA-2026:7329",
            "https://access.redhat.com/errata/RHSA-2026:7477",
            "https://access.redhat.com/security/cve/CVE-2025-9820",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2392528",
            "https://gitlab.com/gnutls/gnutls/-/commit/1d56f96f6ab5034d677136b9d50b5a75dff0faf5",
            "https://gitlab.com/gnutls/gnutls/-/issues/1732",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2025-11-18",
            "http://www.openwall.com/lists/oss-security/2025/11/20/2",
            "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          ],
          "description": "A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 4,
                "exploitabilityScore": 2.6,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-9820",
              "epss": 0.00203,
              "percentile": 0.10523,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-9820",
              "cwe": "CWE-121",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-9820",
            "versionConstraint": "< 3.7.9-2+deb12u6 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u6"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-29477",
        "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-29477",
        "namespace": "nvd:cpe",
        "severity": "Medium",
        "urls": [
          "https://github.com/lmarch2/poc/blob/main/fluent-bit/fluent-bit.md"
        ],
        "description": "An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 0.8,
              "impactScore": 4.8
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-29477",
            "epss": 0.0017,
            "percentile": 0.06648,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-29477",
            "cwe": "CWE-400",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": ""
        },
        "advisories": [],
        "risk": 0.08925
      },
      "relatedVulnerabilities": [],
      "matchDetails": [
        {
          "type": "cpe-match",
          "matcher": "stock-matcher",
          "searchedBy": {
            "namespace": "nvd:cpe",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
            ],
            "package": {
              "name": "fluent-bit",
              "version": "4.1.0"
            }
          },
          "found": {
            "vulnerabilityID": "CVE-2025-29477",
            "versionConstraint": "none (unknown)",
            "cpes": [
              "cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*"
            ]
          }
        }
      ],
      "artifact": {
        "id": "c9f8017f4b3fb0ab",
        "name": "fluent-bit",
        "version": "4.1.0",
        "type": "binary",
        "locations": [
          {
            "path": "/fluent-bit/bin/fluent-bit",
            "layerID": "sha256:0f3590c76e91ee02acf305bdcff2f981bc9f783070524382028f071e8da36d86",
            "accessPath": "/fluent-bit/bin/fluent-bit",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:github/fluent/fluent-bit@4.1.0",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2018-6829",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2018-6829",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2018-6829",
            "epss": 0.01777,
            "percentile": 0.7593,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2018-6829",
            "cwe": "CWE-327",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.08885000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2018-6829",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2018-6829",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/weikengchen/attack-on-libgcrypt-elgamal",
            "https://github.com/weikengchen/attack-on-libgcrypt-elgamal/wiki",
            "https://lists.gnupg.org/pipermail/gcrypt-devel/2018-February/004394.html",
            "https://www.oracle.com/security-alerts/cpujan2020.html"
          ],
          "description": "cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.0",
              "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 10,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2018-6829",
              "epss": 0.01777,
              "percentile": 0.7593,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2018-6829",
              "cwe": "CWE-327",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libgcrypt20",
              "version": "1.10.1-3"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2018-6829",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "aa143951e2980797",
        "name": "libgcrypt20",
        "version": "1.10.1-3",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgcrypt20",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgcrypt20",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgcrypt20:libgcrypt20:1.10.1-3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgcrypt20@1.10.1-3?arch=amd64&distro=debian-12",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-42014",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-42014",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.",
        "cvss": [
          {
            "source": "secalert@redhat.com",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
            "metrics": {
              "baseScore": 6.6,
              "exploitabilityScore": 1.9,
              "impactScore": 4.8
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-42014",
            "epss": 0.0015,
            "percentile": 0.04666,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-42014",
            "cwe": "CWE-825",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.7.9-2+deb12u7"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.7.9-2+deb12u7",
              "date": "2026-05-19",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6281-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6281-1"
          }
        ],
        "risk": 0.087
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-42014",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-42014",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:13274",
            "https://access.redhat.com/errata/RHSA-2026:20611",
            "https://access.redhat.com/errata/RHSA-2026:20612",
            "https://access.redhat.com/errata/RHSA-2026:20613",
            "https://access.redhat.com/errata/RHSA-2026:26319",
            "https://access.redhat.com/errata/RHSA-2026:26409",
            "https://access.redhat.com/errata/RHSA-2026:29197",
            "https://access.redhat.com/errata/RHSA-2026:30004",
            "https://access.redhat.com/errata/RHSA-2026:30849",
            "https://access.redhat.com/errata/RHSA-2026:30850",
            "https://access.redhat.com/errata/RHSA-2026:32962",
            "https://access.redhat.com/errata/RHSA-2026:33125",
            "https://access.redhat.com/errata/RHSA-2026:41921",
            "https://access.redhat.com/errata/RHSA-2026:43575",
            "https://access.redhat.com/security/cve/CVE-2026-42014",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2467451",
            "https://gitlab.com/gnutls/gnutls/-/issues/1766",
            "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-9"
          ],
          "description": "A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
              "metrics": {
                "baseScore": 6.6,
                "exploitabilityScore": 1.9,
                "impactScore": 4.8
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-42014",
              "epss": 0.0015,
              "percentile": 0.04666,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-42014",
              "cwe": "CWE-825",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gnutls28",
              "version": "3.7.9-2+deb12u5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-42014",
            "versionConstraint": "< 3.7.9-2+deb12u7 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.7.9-2+deb12u7"
          }
        }
      ],
      "artifact": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-2379",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2024-2379",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2024-2379",
            "epss": 0.01709,
            "percentile": 0.74978,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-2379",
            "cwe": "CWE-295",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.08545000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-2379",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-2379",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "http://seclists.org/fulldisclosure/2024/Jul/18",
            "http://seclists.org/fulldisclosure/2024/Jul/19",
            "http://seclists.org/fulldisclosure/2024/Jul/20",
            "http://www.openwall.com/lists/oss-security/2024/03/27/2",
            "https://curl.se/docs/CVE-2024-2379.html",
            "https://curl.se/docs/CVE-2024-2379.json",
            "https://hackerone.com/reports/2410774",
            "https://security.netapp.com/advisory/ntap-20240531-0001/",
            "https://support.apple.com/kb/HT214118",
            "https://support.apple.com/kb/HT214119",
            "https://support.apple.com/kb/HT214120"
          ],
          "description": "libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 6.3,
                "exploitabilityScore": 2.9,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-2379",
              "epss": 0.01709,
              "percentile": 0.74978,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-2379",
              "cwe": "CWE-295",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-2379",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-6472",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-6472",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types.  That is to say, the victim will execute arbitrary SQL functions of the attacker's choice.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
        "cvss": [
          {
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 5.4,
              "exploitabilityScore": 2.9,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-6472",
            "epss": 0.00159,
            "percentile": 0.05475,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-6472",
            "cwe": "CWE-862",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.18-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.18-0+deb12u1",
              "date": "2026-05-14",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6269-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6269-1"
          }
        ],
        "risk": 0.08268
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-6472",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-6472",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2026-6472/"
          ],
          "description": "Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types.  That is to say, the victim will execute arbitrary SQL functions of the attacker's choice.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.",
          "cvss": [
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 5.4,
                "exploitabilityScore": 2.9,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-6472",
              "epss": 0.00159,
              "percentile": 0.05475,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-6472",
              "cwe": "CWE-862",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-6472",
            "versionConstraint": "< 15.18-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.18-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-13757",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-13757",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
        "cvss": [
          {
            "source": "secalert@redhat.com",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 6.2,
              "exploitabilityScore": 2.6,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-13757",
            "epss": 0.00136,
            "percentile": 0.03456,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-13757",
            "cwe": "CWE-674",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.07616
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-13757",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-13757",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:37469",
            "https://access.redhat.com/errata/RHSA-2026:38342",
            "https://access.redhat.com/security/cve/CVE-2026-13757",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2494556",
            "https://github.com/advisories/GHSA-p2wm-69qx-x25w"
          ],
          "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 6.2,
                "exploitabilityScore": 2.6,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-13757",
              "epss": 0.00136,
              "percentile": 0.03456,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-13757",
              "cwe": "CWE-674",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "p11-kit",
              "version": "0.24.1-2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-13757",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a45a1ff230c2a77b",
        "name": "libp11-kit0",
        "version": "0.24.1-2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libp11-kit0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libp11-kit0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libp11-kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libp11-kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libp11_kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libp11_kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libp11:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libp11:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libp11-kit0@0.24.1-2?arch=amd64&distro=debian-12&upstream=p11-kit",
        "upstreams": [
          {
            "name": "p11-kit"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-22795",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-22795",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.  Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service.  A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read.  The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 5.5,
              "exploitabilityScore": 1.9,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-22795",
            "epss": 0.00144,
            "percentile": 0.041,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-22795",
            "cwe": "CWE-754",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.18-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.18-1~deb12u2",
              "date": "2026-01-27",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6113-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6113-1"
          }
        ],
        "risk": 0.0756
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-22795",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-22795",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4",
            "https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49",
            "https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12",
            "https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e",
            "https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2",
            "https://openssl-library.org/news/secadv/20260127.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: An invalid or NULL pointer dereference can happen in\nan application processing a malformed PKCS#12 file.\n\nImpact summary: An application processing a malformed PKCS#12 file can be\ncaused to dereference an invalid or NULL pointer on memory read, resulting\nin a Denial of Service.\n\nA type confusion vulnerability exists in PKCS#12 parsing code where\nan ASN1_TYPE union member is accessed without first validating the type,\ncausing an invalid pointer read.\n\nThe location is constrained to a 1-byte address space, meaning any\nattempted pointer manipulation can only target addresses between 0x00 and 0xFF.\nThis range corresponds to the zero page, which is unmapped on most modern\noperating systems and will reliably result in a crash, leading only to a\nDenial of Service. Exploiting this issue also requires a user or application\nto process a maliciously crafted PKCS#12 file. It is uncommon to accept\nuntrusted PKCS#12 files in applications as they are usually used to store\nprivate keys which are trusted by definition. For these reasons, the issue\nwas assessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-22795",
              "epss": 0.00144,
              "percentile": 0.041,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-22795",
              "cwe": "CWE-754",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-22795",
            "versionConstraint": "< 3.0.18-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.18-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-68160",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-68160",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.  Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application.  The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "metrics": {
              "baseScore": 4.7,
              "exploitabilityScore": 1.1,
              "impactScore": 3.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-68160",
            "epss": 0.00152,
            "percentile": 0.04887,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-68160",
            "cwe": "CWE-787",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.18-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.18-1~deb12u2",
              "date": "2026-01-27",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6113-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6113-1"
          }
        ],
        "risk": 0.07372000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-68160",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-68160",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/384011202af92605d926fafe4a0bcd6b65d162ad",
            "https://github.com/openssl/openssl/commit/475c466ef2fbd8fc1df6fae1c3eed9c813fc8ff6",
            "https://github.com/openssl/openssl/commit/4c96fbba618e1940f038012506ee9e21d32ee12c",
            "https://github.com/openssl/openssl/commit/6845c3b6460a98b1ec4e463baa2ea1a63a32d7c0",
            "https://github.com/openssl/openssl/commit/68a7cd2e2816c3a02f4d45a2ce43fc04fac97096",
            "https://openssl-library.org/news/secadv/20260127.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: Writing large, newline-free data into a BIO chain using the\nline-buffering filter where the next BIO performs short writes can trigger\na heap-based out-of-bounds write.\n\nImpact summary: This out-of-bounds write can cause memory corruption which\ntypically results in a crash, leading to Denial of Service for an application.\n\nThe line-buffering BIO filter (BIO_f_linebuffer) is not used by default in\nTLS/SSL data paths. In OpenSSL command-line applications, it is typically\nonly pushed onto stdout/stderr on VMS systems. Third-party applications that\nexplicitly use this filter with a BIO chain that can short-write and that\nwrite large, newline-free data influenced by an attacker would be affected.\nHowever, the circumstances where this could happen are unlikely to be under\nattacker control, and BIO_f_linebuffer is unlikely to be handling non-curated\ndata controlled by an attacker. For that reason the issue was assessed as\nLow severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the BIO implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-68160",
              "epss": 0.00152,
              "percentile": 0.04887,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-68160",
              "cwe": "CWE-787",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-68160",
            "versionConstraint": "< 3.0.18-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.18-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-12817",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-12817",
        "namespace": "debian:distro:debian:12",
        "severity": "Low",
        "urls": [],
        "description": "Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema.  A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail.  Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.",
        "cvss": [
          {
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "metrics": {
              "baseScore": 3.1,
              "exploitabilityScore": 1.7,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-12817",
            "epss": 0.00222,
            "percentile": 0.12921,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-12817",
            "cwe": "CWE-862",
            "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "15.15-0+deb12u1"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "15.15-0+deb12u1",
              "date": "2026-01-19",
              "kind": "first-observed"
            }
          ]
        },
        "advisories": [],
        "risk": 0.06771
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-12817",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-12817",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://www.postgresql.org/support/security/CVE-2025-12817/"
          ],
          "description": "Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema.  A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail.  Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.",
          "cvss": [
            {
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
              "metrics": {
                "baseScore": 3.1,
                "exploitabilityScore": 1.7,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-12817",
              "epss": 0.00222,
              "percentile": 0.12921,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-12817",
              "cwe": "CWE-862",
              "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "postgresql-15",
              "version": "15.14-0+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-12817",
            "versionConstraint": "< 15.15-0+deb12u1 (deb)"
          },
          "fix": {
            "suggestedVersion": "15.15-0+deb12u1"
          }
        }
      ],
      "artifact": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-0725",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-0725",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2025-0725",
            "epss": 0.01218,
            "percentile": 0.65511,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-0725",
            "cwe": "CWE-120",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0609
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-0725",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-0725",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2025-0725.html",
            "https://curl.se/docs/CVE-2025-0725.json",
            "https://hackerone.com/reports/2956023",
            "http://www.openwall.com/lists/oss-security/2025/02/05/3",
            "http://www.openwall.com/lists/oss-security/2025/02/06/2",
            "http://www.openwall.com/lists/oss-security/2025/02/06/4",
            "https://github.com/curl/curl/commit/76f83f0db23846e254d940ec7",
            "https://security.netapp.com/advisory/ntap-20250306-0009/"
          ],
          "description": "When libcurl is asked to perform automatic gzip decompression of\ncontent-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option,\n**using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would\nmake libcurl perform a buffer overflow.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
              "metrics": {
                "baseScore": 7.3,
                "exploitabilityScore": 3.9,
                "impactScore": 3.4
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-0725",
              "epss": 0.01218,
              "percentile": 0.65511,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-0725",
              "cwe": "CWE-120",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-0725",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-26461",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2024-26461",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2024-26461",
            "epss": 0.01128,
            "percentile": 0.63041,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-26461",
            "cwe": "CWE-770",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.056400000000000006
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-26461",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-26461",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md",
            "https://security.netapp.com/advisory/ntap-20240415-0011/"
          ],
          "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-26461",
              "epss": 0.01128,
              "percentile": 0.63041,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-26461",
              "cwe": "CWE-770",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-26461",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "c8948b00cda8062b",
        "name": "libgssapi-krb5-2",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-26461",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2024-26461",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2024-26461",
            "epss": 0.01128,
            "percentile": 0.63041,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-26461",
            "cwe": "CWE-770",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.056400000000000006
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-26461",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-26461",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md",
            "https://security.netapp.com/advisory/ntap-20240415-0011/"
          ],
          "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-26461",
              "epss": 0.01128,
              "percentile": 0.63041,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-26461",
              "cwe": "CWE-770",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-26461",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8f3a478cb18888b8",
        "name": "libk5crypto3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libk5crypto3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libk5crypto3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-26461",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2024-26461",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2024-26461",
            "epss": 0.01128,
            "percentile": 0.63041,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-26461",
            "cwe": "CWE-770",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.056400000000000006
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-26461",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-26461",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md",
            "https://security.netapp.com/advisory/ntap-20240415-0011/"
          ],
          "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-26461",
              "epss": 0.01128,
              "percentile": 0.63041,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-26461",
              "cwe": "CWE-770",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-26461",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "575c8aeb7addaf05",
        "name": "libkrb5-3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5-3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5-3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-26461",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2024-26461",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2024-26461",
            "epss": 0.01128,
            "percentile": 0.63041,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-26461",
            "cwe": "CWE-770",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.056400000000000006
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-26461",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-26461",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md",
            "https://security.netapp.com/advisory/ntap-20240415-0011/"
          ],
          "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 7.5,
                "exploitabilityScore": 3.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-26461",
              "epss": 0.01128,
              "percentile": 0.63041,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-26461",
              "cwe": "CWE-770",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-26461",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "f17cb326c34696aa",
        "name": "libkrb5support0",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5support0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5support0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-2236",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2024-2236",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2024-2236",
            "epss": 0.01114,
            "percentile": 0.62682,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-2236",
            "cwe": "CWE-385",
            "source": "secalert@redhat.com",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.055700000000000006
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-2236",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-2236",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2024:9404",
            "https://access.redhat.com/errata/RHSA-2025:3530",
            "https://access.redhat.com/errata/RHSA-2025:3534",
            "https://access.redhat.com/security/cve/CVE-2024-2236",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2245218",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2268268"
          ],
          "description": "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.9,
                "exploitabilityScore": 2.3,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-2236",
              "epss": 0.01114,
              "percentile": 0.62682,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-2236",
              "cwe": "CWE-385",
              "source": "secalert@redhat.com",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "libgcrypt20",
              "version": "1.10.1-3"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-2236",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "aa143951e2980797",
        "name": "libgcrypt20",
        "version": "1.10.1-3",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgcrypt20",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgcrypt20",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgcrypt20:libgcrypt20:1.10.1-3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgcrypt20@1.10.1-3?arch=amd64&distro=debian-12",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40228",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-40228",
        "namespace": "debian:distro:debian:12",
        "severity": "Low",
        "urls": [],
        "description": "In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "metrics": {
              "baseScore": 3.3,
              "exploitabilityScore": 1.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40228",
            "epss": 0.00173,
            "percentile": 0.07019,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40228",
            "cwe": "CWE-669",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.05449499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40228",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40228",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://www.openwall.com/lists/oss-security/2026/04/08/1",
            "http://www.openwall.com/lists/oss-security/2026/05/05/1"
          ],
          "description": "In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 3.3,
                "exploitabilityScore": 1.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40228",
              "epss": 0.00173,
              "percentile": 0.07019,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40228",
              "cwe": "CWE-669",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "systemd",
              "version": "254.26-1~bpo12+1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40228",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a48fdf88485dfed0",
        "name": "libsystemd0",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libsystemd0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libsystemd0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libsystemd0:libsystemd0:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libsystemd0@254.26-1~bpo12%2B1?arch=amd64&distro=debian-12&upstream=systemd",
        "upstreams": [
          {
            "name": "systemd"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-40228",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-40228",
        "namespace": "debian:distro:debian:12",
        "severity": "Low",
        "urls": [],
        "description": "In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.",
        "cvss": [
          {
            "source": "nvd@nist.gov",
            "type": "Primary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "metrics": {
              "baseScore": 3.3,
              "exploitabilityScore": 1.9,
              "impactScore": 1.5
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2026-40228",
            "epss": 0.00173,
            "percentile": 0.07019,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-40228",
            "cwe": "CWE-669",
            "source": "cve@mitre.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "wont-fix"
        },
        "advisories": [],
        "risk": 0.05449499999999999
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-40228",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-40228",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://www.openwall.com/lists/oss-security/2026/04/08/1",
            "http://www.openwall.com/lists/oss-security/2026/05/05/1"
          ],
          "description": "In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 3.3,
                "exploitabilityScore": 1.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "cve@mitre.org",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 2.9,
                "exploitabilityScore": 1.5,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-40228",
              "epss": 0.00173,
              "percentile": 0.07019,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-40228",
              "cwe": "CWE-669",
              "source": "cve@mitre.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "systemd",
              "version": "254.26-1~bpo12+1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-40228",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "9731dfc4cd168377",
        "name": "systemd",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:systemd:systemd:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/Debian/systemd@254.26-1~bpo12%2B1?distro=Debian",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-69418",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-69418",
        "namespace": "debian:distro:debian:12",
        "severity": "Medium",
        "urls": [],
        "description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
        "cvss": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "version": "3.1",
            "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "metrics": {
              "baseScore": 4,
              "exploitabilityScore": 1.5,
              "impactScore": 2.6
            },
            "vendorMetadata": {}
          }
        ],
        "epss": [
          {
            "cve": "CVE-2025-69418",
            "epss": 0.00115,
            "percentile": 0.01813,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-69418",
            "cwe": "CWE-325",
            "source": "openssl-security@openssl.org",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [
            "3.0.18-1~deb12u2"
          ],
          "state": "fixed",
          "available": [
            {
              "version": "3.0.18-1~deb12u2",
              "date": "2026-01-27",
              "kind": "advisory"
            }
          ]
        },
        "advisories": [
          {
            "id": "DSA-6113-1",
            "link": "https://security-tracker.debian.org/tracker/DSA-6113-1"
          }
        ],
        "risk": 0.051750000000000004
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-69418",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-69418",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/commit/372fc5c77529695b05b4f5b5187691a57ef5dffc",
            "https://github.com/openssl/openssl/commit/4016975d4469cd6b94927c607f7c511385f928d8",
            "https://github.com/openssl/openssl/commit/52d23c86a54adab5ee9f80e48b242b52c4cc2347",
            "https://github.com/openssl/openssl/commit/a7589230356d908c0eca4b969ec4f62106f4f5ae",
            "https://github.com/openssl/openssl/commit/ed40856d7d4ba6cb42779b6770666a65f19cb977",
            "https://openssl-library.org/news/secadv/20260127.txt",
            "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          ],
          "description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
              "metrics": {
                "baseScore": 4,
                "exploitabilityScore": 1.5,
                "impactScore": 2.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-69418",
              "epss": 0.00115,
              "percentile": 0.01813,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-69418",
              "cwe": "CWE-325",
              "source": "openssl-security@openssl.org",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-69418",
            "versionConstraint": "< 3.0.18-1~deb12u2 (deb)"
          },
          "fix": {
            "suggestedVersion": "3.0.18-1~deb12u2"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2022-27943",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2022-27943",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2022-27943",
            "epss": 0.00892,
            "percentile": 0.55776,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2022-27943",
            "cwe": "CWE-674",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04460000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2022-27943",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039",
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
          ],
          "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 8.6,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2022-27943",
              "epss": 0.00892,
              "percentile": 0.55776,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2022-27943",
              "cwe": "CWE-674",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gcc-12",
              "version": "12.2.0-14+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2022-27943",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "963c99b42a0be1ee",
        "name": "gcc-12-base",
        "version": "12.2.0-14+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/gcc-12-base",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/var/lib/dpkg/status.d/gcc-12-base",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/gcc-12-base/copyright",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/usr/share/doc/gcc-12-base/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/gcc-12-base.md5sums",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/var/lib/dpkg/status.d/gcc-12-base.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"
        ],
        "cpes": [
          "cpe:2.3:a:gcc-12-base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc-12-base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc_12_base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc_12_base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc-12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc-12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc_12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc_12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/gcc-12-base@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=gcc-12",
        "upstreams": [
          {
            "name": "gcc-12"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2022-27943",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2022-27943",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2022-27943",
            "epss": 0.00892,
            "percentile": 0.55776,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2022-27943",
            "cwe": "CWE-674",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04460000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2022-27943",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039",
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
          ],
          "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 8.6,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2022-27943",
              "epss": 0.00892,
              "percentile": 0.55776,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2022-27943",
              "cwe": "CWE-674",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gcc-12",
              "version": "12.2.0-14+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2022-27943",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "d36a882b8a3ded0b",
        "name": "libatomic1",
        "version": "12.2.0-14+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libatomic1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libatomic1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libatomic1:libatomic1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libatomic1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=gcc-12",
        "upstreams": [
          {
            "name": "gcc-12"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2022-27943",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2022-27943",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2022-27943",
            "epss": 0.00892,
            "percentile": 0.55776,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2022-27943",
            "cwe": "CWE-674",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04460000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2022-27943",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039",
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
          ],
          "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 8.6,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2022-27943",
              "epss": 0.00892,
              "percentile": 0.55776,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2022-27943",
              "cwe": "CWE-674",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gcc-12",
              "version": "12.2.0-14+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2022-27943",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "531f514be4b1b4c4",
        "name": "libgcc-s1",
        "version": "12.2.0-14+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgcc-s1",
            "layerID": "sha256:c3abae442368dc447f15c468933843c361f227f5d87b2bb86515b49f40583ed9",
            "accessPath": "/var/lib/dpkg/status.d/libgcc-s1",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/gcc-12-base/copyright",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/usr/share/doc/libgcc-s1/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libgcc-s1.md5sums",
            "layerID": "sha256:c3abae442368dc447f15c468933843c361f227f5d87b2bb86515b49f40583ed9",
            "accessPath": "/var/lib/dpkg/status.d/libgcc-s1.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"
        ],
        "cpes": [
          "cpe:2.3:a:libgcc-s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgcc-s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgcc_s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgcc_s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgcc:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgcc:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgcc-s1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=gcc-12",
        "upstreams": [
          {
            "name": "gcc-12"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2022-27943",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2022-27943",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2022-27943",
            "epss": 0.00892,
            "percentile": 0.55776,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2022-27943",
            "cwe": "CWE-674",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04460000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2022-27943",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039",
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
          ],
          "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 8.6,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2022-27943",
              "epss": 0.00892,
              "percentile": 0.55776,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2022-27943",
              "cwe": "CWE-674",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gcc-12",
              "version": "12.2.0-14+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2022-27943",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "1f52ffed9a91c6fe",
        "name": "libgomp1",
        "version": "12.2.0-14+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgomp1",
            "layerID": "sha256:2401c5ea32a75452bc4b02a664c80cf63f197704653926fca19e22e6cbc85652",
            "accessPath": "/var/lib/dpkg/status.d/libgomp1",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libgomp1.md5sums",
            "layerID": "sha256:2401c5ea32a75452bc4b02a664c80cf63f197704653926fca19e22e6cbc85652",
            "accessPath": "/var/lib/dpkg/status.d/libgomp1.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/usr/share/doc/gcc-12-base/copyright",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/usr/share/doc/libgomp1/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"
        ],
        "cpes": [
          "cpe:2.3:a:libgomp1:libgomp1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgomp1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=gcc-12",
        "upstreams": [
          {
            "name": "gcc-12"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2022-27943",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2022-27943",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2022-27943",
            "epss": 0.00892,
            "percentile": 0.55776,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2022-27943",
            "cwe": "CWE-674",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04460000000000001
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2022-27943",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039",
            "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/",
            "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
          ],
          "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 5.5,
                "exploitabilityScore": 1.9,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 8.6,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2022-27943",
              "epss": 0.00892,
              "percentile": 0.55776,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2022-27943",
              "cwe": "CWE-674",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "gcc-12",
              "version": "12.2.0-14+deb12u1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2022-27943",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "22e3c711107504d2",
        "name": "libstdc++6",
        "version": "12.2.0-14+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libstdc++6",
            "layerID": "sha256:6819a1af097df543d58dc30b51f737e55f3f42a9a04e641f175834a55bf0629c",
            "accessPath": "/var/lib/dpkg/status.d/libstdc++6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libstdc++6.md5sums",
            "layerID": "sha256:6819a1af097df543d58dc30b51f737e55f3f42a9a04e641f175834a55bf0629c",
            "accessPath": "/var/lib/dpkg/status.d/libstdc++6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/usr/share/doc/gcc-12-base/copyright",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/usr/share/doc/libstdc++6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"
        ],
        "cpes": [
          "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libstdc%2B%2B6@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=gcc-12",
        "upstreams": [
          {
            "name": "gcc-12"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-26458",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2024-26458",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2024-26458",
            "epss": 0.00815,
            "percentile": 0.53375,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-26458",
            "cwe": "CWE-401",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04075
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-26458",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-26458",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md",
            "https://security.netapp.com/advisory/ntap-20240415-0010/"
          ],
          "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-26458",
              "epss": 0.00815,
              "percentile": 0.53375,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-26458",
              "cwe": "CWE-401",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-26458",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "c8948b00cda8062b",
        "name": "libgssapi-krb5-2",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-26458",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2024-26458",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2024-26458",
            "epss": 0.00815,
            "percentile": 0.53375,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-26458",
            "cwe": "CWE-401",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04075
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-26458",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-26458",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md",
            "https://security.netapp.com/advisory/ntap-20240415-0010/"
          ],
          "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-26458",
              "epss": 0.00815,
              "percentile": 0.53375,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-26458",
              "cwe": "CWE-401",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-26458",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8f3a478cb18888b8",
        "name": "libk5crypto3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libk5crypto3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libk5crypto3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-26458",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2024-26458",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2024-26458",
            "epss": 0.00815,
            "percentile": 0.53375,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-26458",
            "cwe": "CWE-401",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04075
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-26458",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-26458",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md",
            "https://security.netapp.com/advisory/ntap-20240415-0010/"
          ],
          "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-26458",
              "epss": 0.00815,
              "percentile": 0.53375,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-26458",
              "cwe": "CWE-401",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-26458",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "575c8aeb7addaf05",
        "name": "libkrb5-3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5-3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5-3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2024-26458",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2024-26458",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2024-26458",
            "epss": 0.00815,
            "percentile": 0.53375,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2024-26458",
            "cwe": "CWE-401",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.04075
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2024-26458",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2024-26458",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md",
            "https://security.netapp.com/advisory/ntap-20240415-0010/"
          ],
          "description": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2024-26458",
              "epss": 0.00815,
              "percentile": 0.53375,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2024-26458",
              "cwe": "CWE-401",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2024-26458",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "f17cb326c34696aa",
        "name": "libkrb5support0",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5support0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5support0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2013-4392",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2013-4392",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2013-4392",
            "epss": 0.00472,
            "percentile": 0.38229,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2013-4392",
            "cwe": "CWE-59",
            "source": "nvd@nist.gov",
            "type": "Primary"
          },
          {
            "cve": "CVE-2013-4392",
            "cwe": "CWE-59",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.023600000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2013-4392",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2013-4392",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357",
            "http://www.openwall.com/lists/oss-security/2013/10/01/9",
            "https://bugzilla.redhat.com/show_bug.cgi?id=859060"
          ],
          "description": "systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:L/AC:M/Au:N/C:P/I:P/A:N",
              "metrics": {
                "baseScore": 3.3,
                "exploitabilityScore": 3.4,
                "impactScore": 5
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 1.4,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2013-4392",
              "epss": 0.00472,
              "percentile": 0.38229,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2013-4392",
              "cwe": "CWE-59",
              "source": "nvd@nist.gov",
              "type": "Primary"
            },
            {
              "cve": "CVE-2013-4392",
              "cwe": "CWE-59",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "systemd",
              "version": "254.26-1~bpo12+1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2013-4392",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a48fdf88485dfed0",
        "name": "libsystemd0",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libsystemd0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libsystemd0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libsystemd0:libsystemd0:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libsystemd0@254.26-1~bpo12%2B1?arch=amd64&distro=debian-12&upstream=systemd",
        "upstreams": [
          {
            "name": "systemd"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2013-4392",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2013-4392",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2013-4392",
            "epss": 0.00472,
            "percentile": 0.38229,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2013-4392",
            "cwe": "CWE-59",
            "source": "nvd@nist.gov",
            "type": "Primary"
          },
          {
            "cve": "CVE-2013-4392",
            "cwe": "CWE-59",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.023600000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2013-4392",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2013-4392",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357",
            "http://www.openwall.com/lists/oss-security/2013/10/01/9",
            "https://bugzilla.redhat.com/show_bug.cgi?id=859060"
          ],
          "description": "systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:L/AC:M/Au:N/C:P/I:P/A:N",
              "metrics": {
                "baseScore": 3.3,
                "exploitabilityScore": 3.4,
                "impactScore": 5
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 1.4,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2013-4392",
              "epss": 0.00472,
              "percentile": 0.38229,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2013-4392",
              "cwe": "CWE-59",
              "source": "nvd@nist.gov",
              "type": "Primary"
            },
            {
              "cve": "CVE-2013-4392",
              "cwe": "CWE-59",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "systemd",
              "version": "254.26-1~bpo12+1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2013-4392",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "9731dfc4cd168377",
        "name": "systemd",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:systemd:systemd:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/Debian/systemd@254.26-1~bpo12%2B1?distro=Debian",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-15079",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-15079",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2025-15079",
            "epss": 0.00457,
            "percentile": 0.37266,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-15079",
            "cwe": "CWE-297",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.022850000000000002
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-15079",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-15079.html",
            "https://curl.se/docs/CVE-2025-15079.json",
            "https://hackerone.com/reports/3477116",
            "http://www.openwall.com/lists/oss-security/2026/01/07/6"
          ],
          "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-15079",
              "epss": 0.00457,
              "percentile": 0.37266,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-15079",
              "cwe": "CWE-297",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-15079",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-15224",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-15224",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2025-15224",
            "epss": 0.00413,
            "percentile": 0.33881,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-15224",
            "cwe": "CWE-287",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.02065
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-15224",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224",
          "namespace": "nvd:cpe",
          "severity": "Low",
          "urls": [
            "https://curl.se/docs/CVE-2025-15224.html",
            "https://curl.se/docs/CVE-2025-15224.json",
            "https://hackerone.com/reports/3480925",
            "http://www.openwall.com/lists/oss-security/2026/01/07/7"
          ],
          "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 3.1,
                "exploitabilityScore": 1.7,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-15224",
              "epss": 0.00413,
              "percentile": 0.33881,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-15224",
              "cwe": "CWE-287",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-15224",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-10966",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-10966",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms.  This prevents curl from detecting MITM attackers and more.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2025-10966",
            "epss": 0.0039,
            "percentile": 0.31652,
            "date": "2026-07-28"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0195
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-10966",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-10966",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-10966.html",
            "https://curl.se/docs/CVE-2025-10966.json",
            "https://hackerone.com/reports/3355218",
            "http://www.openwall.com/lists/oss-security/2025/11/05/2",
            "https://cert-portal.siemens.com/productcert/html/ssa-253495.html",
            "https://github.com/curl/curl/commit/b011e3fcfb06d6c0278595ee2ee297036fbe9793"
          ],
          "description": "curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
              "metrics": {
                "baseScore": 4.3,
                "exploitabilityScore": 2.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-10966",
              "epss": 0.0039,
              "percentile": 0.31652,
              "date": "2026-07-28"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-10966",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-27587",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-27587",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2025-27587",
            "epss": 0.0037,
            "percentile": 0.29634,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-27587",
            "cwe": "CWE-385",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.018500000000000003
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-27587",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-27587",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/openssl/openssl/issues/24253",
            "https://minerva.crocs.fi.muni.cz"
          ],
          "description": "OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 1.7,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-27587",
              "epss": 0.0037,
              "percentile": 0.29634,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-27587",
              "cwe": "CWE-385",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openssl",
              "version": "3.0.17-1~deb12u2"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-27587",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-31439",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2023-31439",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2023-31439",
            "epss": 0.00352,
            "percentile": 0.27831,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2023-31439",
            "cwe": "CWE-354",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0176
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-31439",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-31439",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/kastel-security/Journald",
            "https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf",
            "https://github.com/systemd/systemd/pull/28885",
            "https://github.com/systemd/systemd/releases"
          ],
          "description": "An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-31439",
              "epss": 0.00352,
              "percentile": 0.27831,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2023-31439",
              "cwe": "CWE-354",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "systemd",
              "version": "254.26-1~bpo12+1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-31439",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a48fdf88485dfed0",
        "name": "libsystemd0",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libsystemd0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libsystemd0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libsystemd0:libsystemd0:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libsystemd0@254.26-1~bpo12%2B1?arch=amd64&distro=debian-12&upstream=systemd",
        "upstreams": [
          {
            "name": "systemd"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-31439",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2023-31439",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2023-31439",
            "epss": 0.00352,
            "percentile": 0.27831,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2023-31439",
            "cwe": "CWE-354",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0176
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-31439",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-31439",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/kastel-security/Journald",
            "https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf",
            "https://github.com/systemd/systemd/pull/28885",
            "https://github.com/systemd/systemd/releases"
          ],
          "description": "An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-31439",
              "epss": 0.00352,
              "percentile": 0.27831,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2023-31439",
              "cwe": "CWE-354",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "systemd",
              "version": "254.26-1~bpo12+1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-31439",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "9731dfc4cd168377",
        "name": "systemd",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:systemd:systemd:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/Debian/systemd@254.26-1~bpo12%2B1?distro=Debian",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2017-14159",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2017-14159",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2017-14159",
            "epss": 0.00349,
            "percentile": 0.27524,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2017-14159",
            "cwe": "CWE-665",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.01745
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2017-14159",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2017-14159",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "http://www.openldap.org/its/index.cgi?findid=8703",
            "https://www.oracle.com/security-alerts/cpuapr2022.html"
          ],
          "description": "slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "metrics": {
                "baseScore": 4.7,
                "exploitabilityScore": 1.1,
                "impactScore": 3.6
              },
              "vendorMetadata": {}
            },
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "2.0",
              "vector": "AV:L/AC:M/Au:N/C:N/I:N/A:P",
              "metrics": {
                "baseScore": 1.9,
                "exploitabilityScore": 3.4,
                "impactScore": 2.9
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2017-14159",
              "epss": 0.00349,
              "percentile": 0.27524,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2017-14159",
              "cwe": "CWE-665",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openldap",
              "version": "2.5.13+dfsg-5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2017-14159",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "919a44d8cbaa32e2",
        "name": "libldap-2.5-0",
        "version": "2.5.13+dfsg-5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12&upstream=openldap",
        "upstreams": [
          {
            "name": "openldap"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-31437",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2023-31437",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2023-31437",
            "epss": 0.00344,
            "percentile": 0.27005,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2023-31437",
            "cwe": "CWE-354",
            "source": "nvd@nist.gov",
            "type": "Primary"
          },
          {
            "cve": "CVE-2023-31437",
            "cwe": "CWE-354",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0172
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-31437",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-31437",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/kastel-security/Journald",
            "https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf",
            "https://github.com/systemd/systemd/releases"
          ],
          "description": "An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-31437",
              "epss": 0.00344,
              "percentile": 0.27005,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2023-31437",
              "cwe": "CWE-354",
              "source": "nvd@nist.gov",
              "type": "Primary"
            },
            {
              "cve": "CVE-2023-31437",
              "cwe": "CWE-354",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "systemd",
              "version": "254.26-1~bpo12+1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-31437",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a48fdf88485dfed0",
        "name": "libsystemd0",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libsystemd0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libsystemd0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libsystemd0:libsystemd0:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libsystemd0@254.26-1~bpo12%2B1?arch=amd64&distro=debian-12&upstream=systemd",
        "upstreams": [
          {
            "name": "systemd"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-31437",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2023-31437",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2023-31437",
            "epss": 0.00344,
            "percentile": 0.27005,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2023-31437",
            "cwe": "CWE-354",
            "source": "nvd@nist.gov",
            "type": "Primary"
          },
          {
            "cve": "CVE-2023-31437",
            "cwe": "CWE-354",
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0172
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-31437",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-31437",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/kastel-security/Journald",
            "https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf",
            "https://github.com/systemd/systemd/releases"
          ],
          "description": "An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            },
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-31437",
              "epss": 0.00344,
              "percentile": 0.27005,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2023-31437",
              "cwe": "CWE-354",
              "source": "nvd@nist.gov",
              "type": "Primary"
            },
            {
              "cve": "CVE-2023-31437",
              "cwe": "CWE-354",
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "systemd",
              "version": "254.26-1~bpo12+1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-31437",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "9731dfc4cd168377",
        "name": "systemd",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:systemd:systemd:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/Debian/systemd@254.26-1~bpo12%2B1?distro=Debian",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-31438",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2023-31438",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2023-31438",
            "epss": 0.00328,
            "percentile": 0.25281,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2023-31438",
            "cwe": "CWE-354",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0164
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-31438",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-31438",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/kastel-security/Journald",
            "https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf",
            "https://github.com/systemd/systemd/pull/28886",
            "https://github.com/systemd/systemd/releases"
          ],
          "description": "An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-31438",
              "epss": 0.00328,
              "percentile": 0.25281,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2023-31438",
              "cwe": "CWE-354",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "systemd",
              "version": "254.26-1~bpo12+1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-31438",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "a48fdf88485dfed0",
        "name": "libsystemd0",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libsystemd0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libsystemd0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libsystemd0:libsystemd0:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libsystemd0@254.26-1~bpo12%2B1?arch=amd64&distro=debian-12&upstream=systemd",
        "upstreams": [
          {
            "name": "systemd"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2023-31438",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2023-31438",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2023-31438",
            "epss": 0.00328,
            "percentile": 0.25281,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2023-31438",
            "cwe": "CWE-354",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0164
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2023-31438",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2023-31438",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://github.com/kastel-security/Journald",
            "https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf",
            "https://github.com/systemd/systemd/pull/28886",
            "https://github.com/systemd/systemd/releases"
          ],
          "description": "An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"",
          "cvss": [
            {
              "source": "nvd@nist.gov",
              "type": "Primary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "metrics": {
                "baseScore": 5.3,
                "exploitabilityScore": 3.9,
                "impactScore": 1.5
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2023-31438",
              "epss": 0.00328,
              "percentile": 0.25281,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2023-31438",
              "cwe": "CWE-354",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-direct-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "systemd",
              "version": "254.26-1~bpo12+1"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2023-31438",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "9731dfc4cd168377",
        "name": "systemd",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:systemd:systemd:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/Debian/systemd@254.26-1~bpo12%2B1?distro=Debian",
        "upstreams": []
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-9547",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-9547",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2026-9547",
            "epss": 0.00325,
            "percentile": 0.24979,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-9547",
            "cwe": "NVD-CWE-Other",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.01625
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-9547",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-9547",
          "namespace": "nvd:cpe",
          "severity": "High",
          "urls": [
            "https://curl.se/docs/CVE-2026-9547.html",
            "https://curl.se/docs/CVE-2026-9547.json",
            "https://hackerone.com/reports/3751712"
          ],
          "description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 7.4,
                "exploitabilityScore": 2.3,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-9547",
              "epss": 0.00325,
              "percentile": 0.24979,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-9547",
              "cwe": "NVD-CWE-Other",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-9547",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11850",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-11850",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2026-11850",
            "epss": 0.00261,
            "percentile": 0.17805,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11850",
            "cwe": "CWE-191",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.01305
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11850",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:25520",
            "https://access.redhat.com/security/cve/CVE-2026-11850",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
          ],
          "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 0.8,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11850",
              "epss": 0.00261,
              "percentile": 0.17805,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11850",
              "cwe": "CWE-191",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11850",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "c8948b00cda8062b",
        "name": "libgssapi-krb5-2",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11850",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-11850",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2026-11850",
            "epss": 0.00261,
            "percentile": 0.17805,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11850",
            "cwe": "CWE-191",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.01305
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11850",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:25520",
            "https://access.redhat.com/security/cve/CVE-2026-11850",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
          ],
          "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 0.8,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11850",
              "epss": 0.00261,
              "percentile": 0.17805,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11850",
              "cwe": "CWE-191",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11850",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "8f3a478cb18888b8",
        "name": "libk5crypto3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libk5crypto3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libk5crypto3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11850",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-11850",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2026-11850",
            "epss": 0.00261,
            "percentile": 0.17805,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11850",
            "cwe": "CWE-191",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.01305
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11850",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:25520",
            "https://access.redhat.com/security/cve/CVE-2026-11850",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
          ],
          "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 0.8,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11850",
              "epss": 0.00261,
              "percentile": 0.17805,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11850",
              "cwe": "CWE-191",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11850",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "575c8aeb7addaf05",
        "name": "libkrb5-3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5-3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5-3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-11850",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-11850",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2026-11850",
            "epss": 0.00261,
            "percentile": 0.17805,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-11850",
            "cwe": "CWE-191",
            "source": "secalert@redhat.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.01305
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-11850",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://access.redhat.com/errata/RHSA-2026:25520",
            "https://access.redhat.com/security/cve/CVE-2026-11850",
            "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
          ],
          "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
          "cvss": [
            {
              "source": "secalert@redhat.com",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H",
              "metrics": {
                "baseScore": 5,
                "exploitabilityScore": 0.8,
                "impactScore": 4.3
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-11850",
              "epss": 0.00261,
              "percentile": 0.17805,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-11850",
              "cwe": "CWE-191",
              "source": "secalert@redhat.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "krb5",
              "version": "1.20.1-2+deb12u4"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-11850",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "f17cb326c34696aa",
        "name": "libkrb5support0",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5support0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5support0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2026-22185",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2026-22185",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2026-22185",
            "epss": 0.00127,
            "percentile": 0.02724,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2026-22185",
            "cwe": "CWE-125",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          },
          {
            "cve": "CVE-2026-22185",
            "cwe": "CWE-191",
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0063500000000000015
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2026-22185",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2026-22185",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://bugs.openldap.org/show_bug.cgi?id=10421",
            "https://seclists.org/fulldisclosure/2026/Jan/5",
            "https://seclists.org/fulldisclosure/2026/Jan/8",
            "https://www.openldap.org/",
            "https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"
          ],
          "description": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.",
          "cvss": [
            {
              "source": "disclosure@vulncheck.com",
              "type": "Secondary",
              "version": "4.0",
              "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "metrics": {
                "baseScore": 4.6
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2026-22185",
              "epss": 0.00127,
              "percentile": 0.02724,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2026-22185",
              "cwe": "CWE-125",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            },
            {
              "cve": "CVE-2026-22185",
              "cwe": "CWE-191",
              "source": "disclosure@vulncheck.com",
              "type": "Secondary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "openldap",
              "version": "2.5.13+dfsg-5"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2026-22185",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "919a44d8cbaa32e2",
        "name": "libldap-2.5-0",
        "version": "2.5.13+dfsg-5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12&upstream=openldap",
        "upstreams": [
          {
            "name": "openldap"
          }
        ]
      }
    },
    {
      "vulnerability": {
        "id": "CVE-2025-14017",
        "dataSource": "https://security-tracker.debian.org/tracker/CVE-2025-14017",
        "namespace": "debian:distro:debian:12",
        "severity": "Negligible",
        "urls": [],
        "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers.  Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.",
        "cvss": [],
        "epss": [
          {
            "cve": "CVE-2025-14017",
            "epss": 0.00106,
            "percentile": 0.01282,
            "date": "2026-07-28"
          }
        ],
        "cwes": [
          {
            "cve": "CVE-2025-14017",
            "cwe": "NVD-CWE-Other",
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ],
        "fix": {
          "versions": [],
          "state": "not-fixed"
        },
        "advisories": [],
        "risk": 0.0053
      },
      "relatedVulnerabilities": [
        {
          "id": "CVE-2025-14017",
          "dataSource": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017",
          "namespace": "nvd:cpe",
          "severity": "Medium",
          "urls": [
            "https://curl.se/docs/CVE-2025-14017.html",
            "https://curl.se/docs/CVE-2025-14017.json",
            "http://www.openwall.com/lists/oss-security/2026/01/07/3"
          ],
          "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
          "cvss": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "type": "Secondary",
              "version": "3.1",
              "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
              "metrics": {
                "baseScore": 6.3,
                "exploitabilityScore": 1.1,
                "impactScore": 5.2
              },
              "vendorMetadata": {}
            }
          ],
          "epss": [
            {
              "cve": "CVE-2025-14017",
              "epss": 0.00106,
              "percentile": 0.01282,
              "date": "2026-07-28"
            }
          ],
          "cwes": [
            {
              "cve": "CVE-2025-14017",
              "cwe": "NVD-CWE-Other",
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        }
      ],
      "matchDetails": [
        {
          "type": "exact-indirect-match",
          "matcher": "dpkg-matcher",
          "searchedBy": {
            "distro": {
              "type": "debian",
              "version": "12"
            },
            "package": {
              "name": "curl",
              "version": "7.88.1-10+deb12u14"
            },
            "namespace": "debian:distro:debian:12"
          },
          "found": {
            "vulnerabilityID": "CVE-2025-14017",
            "versionConstraint": "none (unknown)"
          }
        }
      ],
      "artifact": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      }
    }
  ],
  "alertsByPackage": [
    {
      "package": {
        "id": "0f919d6ebdb73625",
        "name": "libssl3",
        "version": "3.0.17-1~deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssl3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssl3",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libssl3/copyright",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/usr/share/doc/libssl3/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "layerID": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
            "accessPath": "/var/lib/dpkg/status.d/libssl3.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "Apache-2.0",
          "Artistic",
          "GPL-1",
          "GPL-1+"
        ],
        "cpes": [
          "cpe:2.3:a:libssl3:libssl3:3.0.17-1\\~deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssl3@3.0.17-1~deb12u2?arch=amd64&distro=debian-12&upstream=openssl",
        "upstreams": [
          {
            "name": "openssl"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "1f52ffed9a91c6fe",
        "name": "libgomp1",
        "version": "12.2.0-14+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgomp1",
            "layerID": "sha256:2401c5ea32a75452bc4b02a664c80cf63f197704653926fca19e22e6cbc85652",
            "accessPath": "/var/lib/dpkg/status.d/libgomp1",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libgomp1.md5sums",
            "layerID": "sha256:2401c5ea32a75452bc4b02a664c80cf63f197704653926fca19e22e6cbc85652",
            "accessPath": "/var/lib/dpkg/status.d/libgomp1.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/usr/share/doc/gcc-12-base/copyright",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/usr/share/doc/libgomp1/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"
        ],
        "cpes": [
          "cpe:2.3:a:libgomp1:libgomp1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgomp1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=gcc-12",
        "upstreams": [
          {
            "name": "gcc-12"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "22e3c711107504d2",
        "name": "libstdc++6",
        "version": "12.2.0-14+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libstdc++6",
            "layerID": "sha256:6819a1af097df543d58dc30b51f737e55f3f42a9a04e641f175834a55bf0629c",
            "accessPath": "/var/lib/dpkg/status.d/libstdc++6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libstdc++6.md5sums",
            "layerID": "sha256:6819a1af097df543d58dc30b51f737e55f3f42a9a04e641f175834a55bf0629c",
            "accessPath": "/var/lib/dpkg/status.d/libstdc++6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/usr/share/doc/gcc-12-base/copyright",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/usr/share/doc/libstdc++6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"
        ],
        "cpes": [
          "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libstdc%2B%2B6@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=gcc-12",
        "upstreams": [
          {
            "name": "gcc-12"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "22ee1f32510608b7",
        "name": "libnettle8",
        "version": "3.8.1-2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libnettle8",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libnettle8",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libnettle8:libnettle8:3.8.1-2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libnettle8@3.8.1-2?arch=amd64&distro=debian-12&upstream=nettle",
        "upstreams": [
          {
            "name": "nettle"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "26ecde7e69dbfa04",
        "name": "libpsl5",
        "version": "0.21.2-1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpsl5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpsl5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpsl5:libpsl5:0.21.2-1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpsl5@0.21.2-1?arch=amd64&distro=debian-12&upstream=libpsl",
        "upstreams": [
          {
            "name": "libpsl"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "3fc6ff121848d01d",
        "name": "libyaml-0-2",
        "version": "0.2.5-1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libyaml-0-2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libyaml-0-2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libyaml-0-2:libyaml-0-2:0.2.5-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libyaml-0-2:libyaml_0_2:0.2.5-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libyaml_0_2:libyaml-0-2:0.2.5-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libyaml_0_2:libyaml_0_2:0.2.5-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libyaml-0:libyaml-0-2:0.2.5-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libyaml-0:libyaml_0_2:0.2.5-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libyaml_0:libyaml-0-2:0.2.5-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libyaml_0:libyaml_0_2:0.2.5-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libyaml:libyaml-0-2:0.2.5-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libyaml:libyaml_0_2:0.2.5-1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libyaml-0-2@0.2.5-1?arch=amd64&distro=debian-12&upstream=libyaml",
        "upstreams": [
          {
            "name": "libyaml"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "42b546cf79458b62",
        "name": "libc6",
        "version": "2.36-9+deb12u13",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libc6",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/libc6/copyright",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/usr/share/doc/libc6/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libc6.md5sums",
            "layerID": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
            "accessPath": "/var/lib/dpkg/status.d/libc6.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"
        ],
        "cpes": [
          "cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u13:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libc6@2.36-9%2Bdeb12u13?arch=amd64&distro=debian-12&upstream=glibc",
        "upstreams": [
          {
            "name": "glibc"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "4332a74a6aafcedd",
        "name": "librtmp1",
        "version": "2.4+20151223.gitfa8646d.1-2+b2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/librtmp1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/librtmp1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:librtmp1:librtmp1:2.4\\+20151223.gitfa8646d.1-2\\+b2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/librtmp1@2.4%2B20151223.gitfa8646d.1-2%2Bb2?arch=amd64&distro=debian-12&upstream=rtmpdump%402.4%2B20151223.gitfa8646d.1-2",
        "upstreams": [
          {
            "name": "rtmpdump",
            "version": "2.4+20151223.gitfa8646d.1-2"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "472c1368193da0b1",
        "name": "liblzma5",
        "version": "5.4.1-1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/liblzma5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/liblzma5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:liblzma5:liblzma5:5.4.1-1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/liblzma5@5.4.1-1?arch=amd64&distro=debian-12&upstream=xz-utils",
        "upstreams": [
          {
            "name": "xz-utils"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "48b70e4d102cdd4b",
        "name": "libtasn1-6",
        "version": "4.19.0-2+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libtasn1-6",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libtasn1-6",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libtasn1-6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libtasn1-6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libtasn1_6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libtasn1_6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libtasn1:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libtasn1:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libtasn1-6@4.19.0-2%2Bdeb12u1?arch=amd64&distro=debian-12",
        "upstreams": []
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "4b24c77f0499bf0c",
        "name": "liblz4-1",
        "version": "1.9.4-1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/liblz4-1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/liblz4-1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:liblz4-1:liblz4-1:1.9.4-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:liblz4-1:liblz4_1:1.9.4-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:liblz4_1:liblz4-1:1.9.4-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:liblz4_1:liblz4_1:1.9.4-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:liblz4:liblz4-1:1.9.4-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:liblz4:liblz4_1:1.9.4-1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/liblz4-1@1.9.4-1?arch=amd64&distro=debian-12&upstream=lz4",
        "upstreams": [
          {
            "name": "lz4"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "531f514be4b1b4c4",
        "name": "libgcc-s1",
        "version": "12.2.0-14+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgcc-s1",
            "layerID": "sha256:c3abae442368dc447f15c468933843c361f227f5d87b2bb86515b49f40583ed9",
            "accessPath": "/var/lib/dpkg/status.d/libgcc-s1",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/gcc-12-base/copyright",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/usr/share/doc/libgcc-s1/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/libgcc-s1.md5sums",
            "layerID": "sha256:c3abae442368dc447f15c468933843c361f227f5d87b2bb86515b49f40583ed9",
            "accessPath": "/var/lib/dpkg/status.d/libgcc-s1.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"
        ],
        "cpes": [
          "cpe:2.3:a:libgcc-s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgcc-s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgcc_s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgcc_s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgcc:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgcc:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgcc-s1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=gcc-12",
        "upstreams": [
          {
            "name": "gcc-12"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "5458fd103c1e4fd3",
        "name": "libgnutls30",
        "version": "3.7.9-2+deb12u5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgnutls30",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgnutls30",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u5?arch=amd64&distro=debian-12&upstream=gnutls28",
        "upstreams": [
          {
            "name": "gnutls28"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "575c8aeb7addaf05",
        "name": "libkrb5-3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5-3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5-3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "59002f318ddb6670",
        "name": "base-files",
        "version": "12.4+deb12u12",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/base-files",
            "layerID": "sha256:bff7f7a9d44356d8784500366094c66399aa6a2edd990cc70e02e27c84402753",
            "accessPath": "/var/lib/dpkg/status.d/base-files",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/base-files/copyright",
            "layerID": "sha256:bff7f7a9d44356d8784500366094c66399aa6a2edd990cc70e02e27c84402753",
            "accessPath": "/usr/share/doc/base-files/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/base-files.md5sums",
            "layerID": "sha256:bff7f7a9d44356d8784500366094c66399aa6a2edd990cc70e02e27c84402753",
            "accessPath": "/var/lib/dpkg/status.d/base-files.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:fd7e4aae7e7b05f217bcf2d02322825c360e66c52c4c2f1b28d784d6297a1c23"
        ],
        "cpes": [
          "cpe:2.3:a:base-files:base-files:12.4\\+deb12u12:*:*:*:*:*:*:*",
          "cpe:2.3:a:base-files:base_files:12.4\\+deb12u12:*:*:*:*:*:*:*",
          "cpe:2.3:a:base_files:base-files:12.4\\+deb12u12:*:*:*:*:*:*:*",
          "cpe:2.3:a:base_files:base_files:12.4\\+deb12u12:*:*:*:*:*:*:*",
          "cpe:2.3:a:base:base-files:12.4\\+deb12u12:*:*:*:*:*:*:*",
          "cpe:2.3:a:base:base_files:12.4\\+deb12u12:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/base-files@12.4%2Bdeb12u12?arch=amd64&distro=debian-12",
        "upstreams": []
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "5ab8f828207bcd0f",
        "name": "libidn2-0",
        "version": "2.3.3-1+b1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libidn2-0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libidn2-0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libidn2-0:libidn2-0:2.3.3-1\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libidn2-0:libidn2_0:2.3.3-1\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libidn2_0:libidn2-0:2.3.3-1\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libidn2_0:libidn2_0:2.3.3-1\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libidn2:libidn2-0:2.3.3-1\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libidn2:libidn2_0:2.3.3-1\\+b1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libidn2-0@2.3.3-1%2Bb1?arch=amd64&distro=debian-12&upstream=libidn2%402.3.3-1",
        "upstreams": [
          {
            "name": "libidn2",
            "version": "2.3.3-1"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "6a8ad0923210971a",
        "name": "libunistring2",
        "version": "1.0-2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libunistring2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libunistring2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libunistring2:libunistring2:1.0-2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libunistring2@1.0-2?arch=amd64&distro=debian-12&upstream=libunistring",
        "upstreams": [
          {
            "name": "libunistring"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "76e875c485ac6ca4",
        "name": "libsasl2-2",
        "version": "2.1.28+dfsg-10",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libsasl2-2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libsasl2-2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*",
          "cpe:2.3:a:libsasl2-2:libsasl2_2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*",
          "cpe:2.3:a:libsasl2_2:libsasl2-2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*",
          "cpe:2.3:a:libsasl2_2:libsasl2_2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*",
          "cpe:2.3:a:libsasl2:libsasl2-2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*",
          "cpe:2.3:a:libsasl2:libsasl2_2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libsasl2-2@2.1.28%2Bdfsg-10?arch=amd64&distro=debian-12&upstream=cyrus-sasl2",
        "upstreams": [
          {
            "name": "cyrus-sasl2"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "7b756a4c6b6cb784",
        "name": "libcurl4",
        "version": "7.88.1-10+deb12u14",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcurl4",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcurl4",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u14:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u14?arch=amd64&distro=debian-12&upstream=curl",
        "upstreams": [
          {
            "name": "curl"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "7fba61587556f31d",
        "name": "libnghttp2-14",
        "version": "1.52.0-1+deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libnghttp2-14",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libnghttp2-14",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2:libnghttp2-14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libnghttp2:libnghttp2_14:1.52.0-1\\+deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libnghttp2-14@1.52.0-1%2Bdeb12u2?arch=amd64&distro=debian-12&upstream=nghttp2",
        "upstreams": [
          {
            "name": "nghttp2"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "81fa76b13d51bb43",
        "name": "media-types",
        "version": "10.0.0",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/media-types",
            "layerID": "sha256:114dde0fefebbca13165d0da9c500a66190e497a82a53dcaabc3172d630be1e9",
            "accessPath": "/var/lib/dpkg/status.d/media-types",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/media-types/copyright",
            "layerID": "sha256:114dde0fefebbca13165d0da9c500a66190e497a82a53dcaabc3172d630be1e9",
            "accessPath": "/usr/share/doc/media-types/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/media-types.md5sums",
            "layerID": "sha256:114dde0fefebbca13165d0da9c500a66190e497a82a53dcaabc3172d630be1e9",
            "accessPath": "/var/lib/dpkg/status.d/media-types.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "ad-hoc"
        ],
        "cpes": [
          "cpe:2.3:a:media-types:media-types:10.0.0:*:*:*:*:*:*:*",
          "cpe:2.3:a:media-types:media_types:10.0.0:*:*:*:*:*:*:*",
          "cpe:2.3:a:media_types:media-types:10.0.0:*:*:*:*:*:*:*",
          "cpe:2.3:a:media_types:media_types:10.0.0:*:*:*:*:*:*:*",
          "cpe:2.3:a:media:media-types:10.0.0:*:*:*:*:*:*:*",
          "cpe:2.3:a:media:media_types:10.0.0:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/media-types@10.0.0?arch=all&distro=debian-12",
        "upstreams": []
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "8905b74027385650",
        "name": "libssh2-1",
        "version": "1.10.0-3+b1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libssh2-1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libssh2-1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12&upstream=libssh2%401.10.0-3",
        "upstreams": [
          {
            "name": "libssh2",
            "version": "1.10.0-3"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "8ebb6fc734ae3ca2",
        "name": "libzstd1",
        "version": "1.5.4+dfsg2-5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libzstd1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libzstd1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libzstd1:libzstd1:1.5.4\\+dfsg2-5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libzstd1@1.5.4%2Bdfsg2-5?arch=amd64&distro=debian-12&upstream=libzstd",
        "upstreams": [
          {
            "name": "libzstd"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "8f3a478cb18888b8",
        "name": "libk5crypto3",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libk5crypto3",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libk5crypto3",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "919a44d8cbaa32e2",
        "name": "libldap-2.5-0",
        "version": "2.5.13+dfsg-5",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libldap-2.5-0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*",
          "cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12&upstream=openldap",
        "upstreams": [
          {
            "name": "openldap"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "9534d60a97673a0b",
        "name": "libhogweed6",
        "version": "3.8.1-2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libhogweed6",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libhogweed6",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libhogweed6:libhogweed6:3.8.1-2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libhogweed6@3.8.1-2?arch=amd64&distro=debian-12&upstream=nettle",
        "upstreams": [
          {
            "name": "nettle"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "963c99b42a0be1ee",
        "name": "gcc-12-base",
        "version": "12.2.0-14+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/gcc-12-base",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/var/lib/dpkg/status.d/gcc-12-base",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/gcc-12-base/copyright",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/usr/share/doc/gcc-12-base/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/gcc-12-base.md5sums",
            "layerID": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
            "accessPath": "/var/lib/dpkg/status.d/gcc-12-base.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"
        ],
        "cpes": [
          "cpe:2.3:a:gcc-12-base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc-12-base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc_12_base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc_12_base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc-12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc-12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc_12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc_12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:gcc:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/gcc-12-base@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=gcc-12",
        "upstreams": [
          {
            "name": "gcc-12"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "9731dfc4cd168377",
        "name": "systemd",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.37.0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:systemd:systemd:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/Debian/systemd@254.26-1~bpo12%2B1?distro=Debian",
        "upstreams": []
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "a45a1ff230c2a77b",
        "name": "libp11-kit0",
        "version": "0.24.1-2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libp11-kit0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libp11-kit0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libp11-kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libp11-kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libp11_kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libp11_kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libp11:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libp11:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libp11-kit0@0.24.1-2?arch=amd64&distro=debian-12&upstream=p11-kit",
        "upstreams": [
          {
            "name": "p11-kit"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "a48fdf88485dfed0",
        "name": "libsystemd0",
        "version": "254.26-1~bpo12+1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libsystemd0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libsystemd0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libsystemd0:libsystemd0:254.26-1\\~bpo12\\+1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libsystemd0@254.26-1~bpo12%2B1?arch=amd64&distro=debian-12&upstream=systemd",
        "upstreams": [
          {
            "name": "systemd"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "a55e64e0eb914b2a",
        "name": "libcap2",
        "version": "1:2.66-4+deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcap2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcap2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcap2:libcap2:1\\:2.66-4\\+deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcap2@1%3A2.66-4%2Bdeb12u2?arch=amd64&distro=debian-12",
        "upstreams": []
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "aa143951e2980797",
        "name": "libgcrypt20",
        "version": "1.10.1-3",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgcrypt20",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgcrypt20",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgcrypt20:libgcrypt20:1.10.1-3:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgcrypt20@1.10.1-3?arch=amd64&distro=debian-12",
        "upstreams": []
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "ac6a16c69ab42e04",
        "name": "tzdata",
        "version": "2025b-0+deb12u2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/tzdata",
            "layerID": "sha256:4840c7c54023c867f19564429c89ddae4e9589c83dce82492183a7e9f7dab1fa",
            "accessPath": "/var/lib/dpkg/status.d/tzdata",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/tzdata/copyright",
            "layerID": "sha256:4840c7c54023c867f19564429c89ddae4e9589c83dce82492183a7e9f7dab1fa",
            "accessPath": "/usr/share/doc/tzdata/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/tzdata.md5sums",
            "layerID": "sha256:4840c7c54023c867f19564429c89ddae4e9589c83dce82492183a7e9f7dab1fa",
            "accessPath": "/var/lib/dpkg/status.d/tzdata.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "public-domain"
        ],
        "cpes": [
          "cpe:2.3:a:tzdata:tzdata:2025b-0\\+deb12u2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/tzdata@2025b-0%2Bdeb12u2?arch=all&distro=debian-12",
        "upstreams": []
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "aefc39f8981b26da",
        "name": "libgpg-error0",
        "version": "1.46-1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgpg-error0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgpg-error0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgpg-error0:libgpg-error0:1.46-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgpg-error0:libgpg_error0:1.46-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgpg_error0:libgpg-error0:1.46-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgpg_error0:libgpg_error0:1.46-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgpg:libgpg-error0:1.46-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgpg:libgpg_error0:1.46-1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgpg-error0@1.46-1?arch=amd64&distro=debian-12&upstream=libgpg-error",
        "upstreams": [
          {
            "name": "libgpg-error"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "c635b43528452638",
        "name": "libbrotli1",
        "version": "1.0.9-2+b6",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libbrotli1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libbrotli1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libbrotli1:libbrotli1:1.0.9-2\\+b6:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libbrotli1@1.0.9-2%2Bb6?arch=amd64&distro=debian-12&upstream=brotli%401.0.9-2",
        "upstreams": [
          {
            "name": "brotli",
            "version": "1.0.9-2"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "c8948b00cda8062b",
        "name": "libgssapi-krb5-2",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgssapi-krb5-2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*",
          "cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "c9f8017f4b3fb0ab",
        "name": "fluent-bit",
        "version": "4.1.0",
        "type": "binary",
        "locations": [
          {
            "path": "/fluent-bit/bin/fluent-bit",
            "layerID": "sha256:0f3590c76e91ee02acf305bdcff2f981bc9f783070524382028f071e8da36d86",
            "accessPath": "/fluent-bit/bin/fluent-bit",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:github/fluent/fluent-bit@4.1.0",
        "upstreams": []
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "ca40227a4415e447",
        "name": "zlib1g",
        "version": "1:1.2.13.dfsg-1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/zlib1g",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/zlib1g",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/zlib1g@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12&upstream=zlib",
        "upstreams": [
          {
            "name": "zlib"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "d36a882b8a3ded0b",
        "name": "libatomic1",
        "version": "12.2.0-14+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libatomic1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libatomic1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libatomic1:libatomic1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libatomic1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=gcc-12",
        "upstreams": [
          {
            "name": "gcc-12"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "da0ab4ee51b298d8",
        "name": "libpq5",
        "version": "15.14-0+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libpq5",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libpq5",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libpq5:libpq5:15.14-0\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libpq5@15.14-0%2Bdeb12u1?arch=amd64&distro=debian-12&upstream=postgresql-15",
        "upstreams": [
          {
            "name": "postgresql-15"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "dca42f6ba1d88ca7",
        "name": "libffi8",
        "version": "3.4.4-1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libffi8",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libffi8",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libffi8:libffi8:3.4.4-1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libffi8@3.4.4-1?arch=amd64&distro=debian-12&upstream=libffi",
        "upstreams": [
          {
            "name": "libffi"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "e258a08cab218252",
        "name": "pkg-config",
        "version": "1.8.1-1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/pkg-config",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/pkg-config",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:pkg-config:pkg-config:1.8.1-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:pkg-config:pkg_config:1.8.1-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:pkg_config:pkg-config:1.8.1-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:pkg_config:pkg_config:1.8.1-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:pkg:pkg-config:1.8.1-1:*:*:*:*:*:*:*",
          "cpe:2.3:a:pkg:pkg_config:1.8.1-1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/pkg-config@1.8.1-1?arch=amd64&distro=debian-12&upstream=pkgconf",
        "upstreams": [
          {
            "name": "pkgconf"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "f051a8fe09c1d5b7",
        "name": "libcom-err2",
        "version": "1.47.0-2+b2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libcom-err2",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libcom-err2",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libcom-err2:libcom-err2:1.47.0-2\\+b2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcom-err2:libcom_err2:1.47.0-2\\+b2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcom_err2:libcom-err2:1.47.0-2\\+b2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcom_err2:libcom_err2:1.47.0-2\\+b2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcom:libcom-err2:1.47.0-2\\+b2:*:*:*:*:*:*:*",
          "cpe:2.3:a:libcom:libcom_err2:1.47.0-2\\+b2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libcom-err2@1.47.0-2%2Bb2?arch=amd64&distro=debian-12&upstream=e2fsprogs%401.47.0-2",
        "upstreams": [
          {
            "name": "e2fsprogs",
            "version": "1.47.0-2"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "f17cb326c34696aa",
        "name": "libkrb5support0",
        "version": "1.20.1-2+deb12u4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkrb5support0",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkrb5support0",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u4?arch=amd64&distro=debian-12&upstream=krb5",
        "upstreams": [
          {
            "name": "krb5"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "f28ae05ddd844b33",
        "name": "netbase",
        "version": "6.4",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/netbase",
            "layerID": "sha256:8fa10c0194df9b7c054c90dbe482585f768a54428fc90a5b78a0066a123b1bba",
            "accessPath": "/var/lib/dpkg/status.d/netbase",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/netbase/copyright",
            "layerID": "sha256:8fa10c0194df9b7c054c90dbe482585f768a54428fc90a5b78a0066a123b1bba",
            "accessPath": "/usr/share/doc/netbase/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          },
          {
            "path": "/var/lib/dpkg/status.d/netbase.md5sums",
            "layerID": "sha256:8fa10c0194df9b7c054c90dbe482585f768a54428fc90a5b78a0066a123b1bba",
            "accessPath": "/var/lib/dpkg/status.d/netbase.md5sums",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPL-2"
        ],
        "cpes": [
          "cpe:2.3:a:netbase:netbase:6.4:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/netbase@6.4?arch=all&distro=debian-12",
        "upstreams": []
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "f6d1dead66cdc801",
        "name": "libgmp10",
        "version": "2:6.2.1+dfsg1-1.1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libgmp10",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libgmp10",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libgmp10:libgmp10:2\\:6.2.1\\+dfsg1-1.1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libgmp10@2%3A6.2.1%2Bdfsg1-1.1?arch=amd64&distro=debian-12&upstream=gmp",
        "upstreams": [
          {
            "name": "gmp"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "fc9f32d36e0ec03a",
        "name": "ca-certificates",
        "version": "20230311+deb12u1",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/ca-certificates",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/ca-certificates",
            "annotations": {
              "evidence": "primary"
            }
          },
          {
            "path": "/usr/share/doc/ca-certificates/copyright",
            "layerID": "sha256:bfe9137a1b044e8097cdfcb6899137a8a984ed70931ed1e8ef0cf7e023a139fc",
            "accessPath": "/usr/share/doc/ca-certificates/copyright",
            "annotations": {
              "evidence": "supporting"
            }
          }
        ],
        "language": "",
        "licenses": [
          "GPL-2",
          "GPL-2+",
          "MPL-2.0"
        ],
        "cpes": [
          "cpe:2.3:a:ca-certificates:ca-certificates:20230311\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:ca-certificates:ca_certificates:20230311\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:ca_certificates:ca-certificates:20230311\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:ca_certificates:ca_certificates:20230311\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:ca:ca-certificates:20230311\\+deb12u1:*:*:*:*:*:*:*",
          "cpe:2.3:a:ca:ca_certificates:20230311\\+deb12u1:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/ca-certificates@20230311%2Bdeb12u1?arch=all&distro=debian-12",
        "upstreams": []
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    },
    {
      "package": {
        "id": "fffb37b9240d6c2f",
        "name": "libkeyutils1",
        "version": "1.6.3-2",
        "type": "deb",
        "locations": [
          {
            "path": "/var/lib/dpkg/status.d/libkeyutils1",
            "layerID": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
            "accessPath": "/var/lib/dpkg/status.d/libkeyutils1",
            "annotations": {
              "evidence": "primary"
            }
          }
        ],
        "language": "",
        "licenses": [],
        "cpes": [
          "cpe:2.3:a:libkeyutils1:libkeyutils1:1.6.3-2:*:*:*:*:*:*:*"
        ],
        "purl": "pkg:deb/debian/libkeyutils1@1.6.3-2?arch=amd64&distro=debian-12&upstream=keyutils",
        "upstreams": [
          {
            "name": "keyutils"
          }
        ]
      },
      "alerts": [
        {
          "type": "distro-eol",
          "message": "Package is from end-of-life distro: debian 12",
          "metadata": {
            "name": "debian",
            "version": "12"
          }
        }
      ]
    }
  ],
  "source": {
    "type": "image",
    "target": {
      "userInput": "ghcr.io/fluent/fluent-bit:4.1.0",
      "imageID": "sha256:5eeaa30aa8c495bc60133caf2137e985430a581745a4aa03213472c3389861cb",
      "manifestDigest": "sha256:1147d5faf6bb6066f921ce6e9028f7ac4846346993279cbbd4d8129eea12868d",
      "mediaType": "application/vnd.docker.distribution.manifest.v2+json",
      "tags": [
        "ghcr.io/fluent/fluent-bit:4.1.0"
      ],
      "imageSize": 108151904,
      "layers": [
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:bff7f7a9d44356d8784500366094c66399aa6a2edd990cc70e02e27c84402753",
          "size": 270695
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:8fa10c0194df9b7c054c90dbe482585f768a54428fc90a5b78a0066a123b1bba",
          "size": 22888
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:4840c7c54023c867f19564429c89ddae4e9589c83dce82492183a7e9f7dab1fa",
          "size": 1464662
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:114dde0fefebbca13165d0da9c500a66190e497a82a53dcaabc3172d630be1e9",
          "size": 82129
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:4d049f83d9cf21d1f5cc0e11deaf36df02790d0e60c1a3829538fb4b61685368",
          "size": 0
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:af5aa97ebe6ce1604747ec1e21af7136ded391bcabe4acef882e718a87c86bcc",
          "size": 149
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:6f1cdceb6a3146f0ccb986521156bef8a422cdbb0863396f7f751f575ba308f4",
          "size": 0
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:bbb6cacb8c82e4da4e8143e03351e939eab5e21ce0ef333c42e637af86c5217b",
          "size": 64
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:2a92d6ac9e4fcc274d5168b217ca4458a9fec6f094ead68d99c77073f08caac1",
          "size": 0
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:1a73b54f556b477f0a8b939d13c504a3b4f4db71f7a09c63afbc10acb3de5849",
          "size": 497
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:f4aee9e53c42a22ed82451218c3ea03d1eea8d6ca8fbe8eb4e950304ba8a8bb3",
          "size": 346
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:bfe9137a1b044e8097cdfcb6899137a8a984ed70931ed1e8ef0cf7e023a139fc",
          "size": 235531
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:bd29502adf199ad9c03afba9bc79df572a26ec60a2a6ffdda4883a5b7a1632fe",
          "size": 12825148
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:2e4983c761ce4933ecec23c31173fed551a237c8d0ba359b697de64bd953a7c3",
          "size": 5901043
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:7095412417d2dce289b77f7a8c632a07c82b707fe43cfef7368c3b65c8d2538a",
          "size": 94016
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:2401c5ea32a75452bc4b02a664c80cf63f197704653926fca19e22e6cbc85652",
          "size": 291001
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:6819a1af097df543d58dc30b51f737e55f3f42a9a04e641f175834a55bf0629c",
          "size": 2311333
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:c3abae442368dc447f15c468933843c361f227f5d87b2bb86515b49f40583ed9",
          "size": 126113
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:86fa2649786cc0925c0034adaf3ae286626382a50b431c29a3896af91fd013e8",
          "size": 16642538
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:9cfdbf08532710c3dabd819310a47dd6dcca01904f64c1f23d917f7422151c3b",
          "size": 217681
        },
        {
          "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
          "digest": "sha256:0f3590c76e91ee02acf305bdcff2f981bc9f783070524382028f071e8da36d86",
          "size": 67666070
        }
      ],
      "manifest": "eyJzY2hlbWFWZXJzaW9uIjoyLCJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmRpc3RyaWJ1dGlvbi5tYW5pZmVzdC52Mitqc29uIiwiY29uZmlnIjp7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuY29udGFpbmVyLmltYWdlLnYxK2pzb24iLCJzaXplIjo1MzA2LCJkaWdlc3QiOiJzaGEyNTY6NWVlYWEzMGFhOGM0OTViYzYwMTMzY2FmMjEzN2U5ODU0MzBhNTgxNzQ1YTRhYTAzMjEzNDcyYzMzODk4NjFjYiJ9LCJsYXllcnMiOlt7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjozMjc2ODAsImRpZ2VzdCI6InNoYTI1NjpiZmY3ZjdhOWQ0NDM1NmQ4Nzg0NTAwMzY2MDk0YzY2Mzk5YWE2YTJlZGQ5OTBjYzcwZTAyZTI3Yzg0NDAyNzUzIn0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6NDA5NjAsImRpZ2VzdCI6InNoYTI1Njo4ZmExMGMwMTk0ZGY5YjdjMDU0YzkwZGJlNDgyNTg1Zjc2OGE1NDQyOGZjOTBhNWI3OGEwMDY2YTEyM2IxYmJhIn0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6MjQwNjQwMCwiZGlnZXN0Ijoic2hhMjU2OjQ4NDBjN2M1NDAyM2M4NjdmMTk1NjQ0MjljODlkZGFlNGU5NTg5YzgzZGNlODI0OTIxODNhN2U5ZjdkYWIxZmEifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjoxMDI0MDAsImRpZ2VzdCI6InNoYTI1NjoxMTRkZGUwZmVmZWJiY2ExMzE2NWQwZGE5YzUwMGE2NjE5MGU0OTdhODJhNTNkY2FhYmMzMTcyZDYzMGJlMWU5In0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6MTUzNiwiZGlnZXN0Ijoic2hhMjU2OjRkMDQ5ZjgzZDljZjIxZDFmNWNjMGUxMWRlYWYzNmRmMDI3OTBkMGU2MGMxYTM4Mjk1MzhmYjRiNjE2ODUzNjgifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjoyNTYwLCJkaWdlc3QiOiJzaGEyNTY6YWY1YWE5N2ViZTZjZTE2MDQ3NDdlYzFlMjFhZjcxMzZkZWQzOTFiY2FiZTRhY2VmODgyZTcxOGE4N2M4NmJjYyJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjI1NjAsImRpZ2VzdCI6InNoYTI1Njo2ZjFjZGNlYjZhMzE0NmYwY2NiOTg2NTIxMTU2YmVmOGE0MjJjZGJiMDg2MzM5NmY3Zjc1MWY1NzViYTMwOGY0In0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6MjU2MCwiZGlnZXN0Ijoic2hhMjU2OmJiYjZjYWNiOGM4MmU0ZGE0ZTgxNDNlMDMzNTFlOTM5ZWFiNWUyMWNlMGVmMzMzYzQyZTYzN2FmODZjNTIxN2IifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjoxNTM2LCJkaWdlc3QiOiJzaGEyNTY6MmE5MmQ2YWM5ZTRmY2MyNzRkNTE2OGIyMTdjYTQ0NThhOWZlYzZmMDk0ZWFkNjhkOTljNzcwNzNmMDhjYWFjMSJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjEwMjQwLCJkaWdlc3QiOiJzaGEyNTY6MWE3M2I1NGY1NTZiNDc3ZjBhOGI5MzlkMTNjNTA0YTNiNGY0ZGI3MWY3YTA5YzYzYWZiYzEwYWNiM2RlNTg0OSJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjMwNzIsImRpZ2VzdCI6InNoYTI1NjpmNGFlZTllNTNjNDJhMjJlZDgyNDUxMjE4YzNlYTAzZDFlZWE4ZDZjYThmYmU4ZWI0ZTk1MDMwNGJhOGE4YmIzIn0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6MjQxNjY0LCJkaWdlc3QiOiJzaGEyNTY6YmZlOTEzN2ExYjA0NGU4MDk3Y2RmY2I2ODk5MTM3YThhOTg0ZWQ3MDkzMWVkMWU4ZWYwY2Y3ZTAyM2ExMzlmYyJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjEzMDY2MjQwLCJkaWdlc3QiOiJzaGEyNTY6YmQyOTUwMmFkZjE5OWFkOWMwM2FmYmE5YmM3OWRmNTcyYTI2ZWM2MGEyYTZmZmRkYTQ4ODNhNWI3YTE2MzJmZSJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjU5MTg3MjAsImRpZ2VzdCI6InNoYTI1NjoyZTQ5ODNjNzYxY2U0OTMzZWNlYzIzYzMxMTczZmVkNTUxYTIzN2M4ZDBiYTM1OWI2OTdkZTY0YmQ5NTNhN2MzIn0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6MTEyNjQwLCJkaWdlc3QiOiJzaGEyNTY6NzA5NTQxMjQxN2QyZGNlMjg5Yjc3ZjdhOGM2MzJhMDdjODJiNzA3ZmU0M2NmZWY3MzY4YzNiNjVjOGQyNTM4YSJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjMwNzIwMCwiZGlnZXN0Ijoic2hhMjU2OjI0MDFjNWVhMzJhNzU0NTJiYzRiMDJhNjY0YzgwY2Y2M2YxOTc3MDQ2NTM5MjZmY2ExOWUyMmU2Y2JjODU2NTIifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjoyMzM0NzIwLCJkaWdlc3QiOiJzaGEyNTY6NjgxOWExYWYwOTdkZjU0M2Q1OGRjMzBiNTFmNzM3ZTU1ZjNmNDJhOWEwNGU2NDFmMTc1ODM0YTU1YmYwNjI5YyJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjE0MzM2MCwiZGlnZXN0Ijoic2hhMjU2OmMzYWJhZTQ0MjM2OGRjNDQ3ZjE1YzQ2ODkzMzg0M2MzNjFmMjI3ZjVkODdiMmJiODY1MTViNDlmNDA1ODNlZDkifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjoxNjkxNjQ4MCwiZGlnZXN0Ijoic2hhMjU2Ojg2ZmEyNjQ5Nzg2Y2MwOTI1YzAwMzRhZGFmM2FlMjg2NjI2MzgyYTUwYjQzMWMyOWEzODk2YWY5MWZkMDEzZTgifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjozNzAxNzYsImRpZ2VzdCI6InNoYTI1Njo5Y2ZkYmYwODUzMjcxMGMzZGFiZDgxOTMxMGE0N2RkNmRjY2EwMTkwNGY2NGMxZjIzZDkxN2Y3NDIyMTUxYzNiIn0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6Njc2NzY2NzIsImRpZ2VzdCI6InNoYTI1NjowZjM1OTBjNzZlOTFlZTAyYWNmMzA1YmRjZmYyZjk4MWJjOWY3ODMwNzA1MjQzODIwMjhmMDcxZThkYTM2ZDg2In1dfQ==",
      "config": "eyJhcmNoaXRlY3R1cmUiOiJhbWQ2NCIsImNvbmZpZyI6eyJVc2VyIjoiMCIsIkV4cG9zZWRQb3J0cyI6eyIyMDIwL3RjcCI6e319LCJFbnYiOlsiUEFUSD0vdXNyL2xvY2FsL3NiaW46L3Vzci9sb2NhbC9iaW46L3Vzci9zYmluOi91c3IvYmluOi9zYmluOi9iaW4iLCJTU0xfQ0VSVF9GSUxFPS9ldGMvc3NsL2NlcnRzL2NhLWNlcnRpZmljYXRlcy5jcnQiLCJGTFVFTlRfQklUX1ZFUlNJT049NC4xLjAiXSwiRW50cnlwb2ludCI6WyIvZmx1ZW50LWJpdC9iaW4vZmx1ZW50LWJpdCJdLCJDbWQiOlsiL2ZsdWVudC1iaXQvYmluL2ZsdWVudC1iaXQiLCItYyIsIi9mbHVlbnQtYml0L2V0Yy9mbHVlbnQtYml0LmNvbmYiXSwiV29ya2luZ0RpciI6Ii8iLCJMYWJlbHMiOnsiYXV0aG9yIjoiRWR1YXJkbyBTaWx2YSBcdTAwM2NlZHVhcmRvLnNpbHZhQGNocm9ub3NwaGVyZS5pb1x1MDAzZSIsImRlc2NyaXB0aW9uIjoiRmx1ZW50IEJpdCBtdWx0aS1hcmNoaXRlY3R1cmUgY29udGFpbmVyIGltYWdlIiwib3JnLm9wZW5jb250YWluZXJzLmltYWdlLmF1dGhvcnMiOiJFZHVhcmRvIFNpbHZhIFx1MDAzY2VkdWFyZG8uc2lsdmFAY2hyb25vc3BoZXJlLmlvXHUwMDNlIiwib3JnLm9wZW5jb250YWluZXJzLmltYWdlLmRlc2NyaXB0aW9uIjoiRmx1ZW50IEJpdCBjb250YWluZXIgaW1hZ2UiLCJvcmcub3BlbmNvbnRhaW5lcnMuaW1hZ2UuZG9jdW1lbnRhdGlvbiI6Imh0dHBzOi8vZG9jcy5mbHVlbnRiaXQuaW8vIiwib3JnLm9wZW5jb250YWluZXJzLmltYWdlLmxpY2Vuc2VzIjoiQXBhY2hlLTIuMCIsIm9yZy5vcGVuY29udGFpbmVycy5pbWFnZS5zb3VyY2UiOiJodHRwczovL2dpdGh1Yi5jb20vZmx1ZW50L2ZsdWVudC1iaXQiLCJvcmcub3BlbmNvbnRhaW5lcnMuaW1hZ2UudGl0bGUiOiJGbHVlbnQgQml0Iiwib3JnLm9wZW5jb250YWluZXJzLmltYWdlLnZlbmRvciI6IkZsdWVudCBPcmdhbml6YXRpb24iLCJvcmcub3BlbmNvbnRhaW5lcnMuaW1hZ2UudmVyc2lvbiI6IjQuMS4wIiwidmVuZG9yIjoiRmx1ZW50IE9yZ2FuaXphdGlvbiIsInZlcnNpb24iOiI0LjEuMCJ9LCJBcmdzRXNjYXBlZCI6dHJ1ZX0sImNyZWF0ZWQiOiIyMDI1LTA5LTI0VDE1OjU1OjQ4LjA0ODI0MDM4N1oiLCJoaXN0b3J5IjpbeyJjcmVhdGVkIjoiMDAwMS0wMS0wMVQwMDowMDowMFoifSx7ImNyZWF0ZWQiOiIwMDAxLTAxLTAxVDAwOjAwOjAwWiJ9LHsiY3JlYXRlZCI6IjAwMDEtMDEtMDFUMDA6MDA6MDBaIn0seyJjcmVhdGVkIjoiMDAwMS0wMS0wMVQwMDowMDowMFoifSx7ImNyZWF0ZWQiOiIwMDAxLTAxLTAxVDAwOjAwOjAwWiJ9LHsiY3JlYXRlZCI6IjAwMDEtMDEtMDFUMDA6MDA6MDBaIn0seyJjcmVhdGVkIjoiMDAwMS0wMS0wMVQwMDowMDowMFoifSx7ImNyZWF0ZWQiOiIwMDAxLTAxLTAxVDAwOjAwOjAwWiJ9LHsiY3JlYXRlZCI6IjAwMDEtMDEtMDFUMDA6MDA6MDBaIn0seyJjcmVhdGVkIjoiMDAwMS0wMS0wMVQwMDowMDowMFoifSx7ImNyZWF0ZWQiOiIwMDAxLTAxLTAxVDAwOjAwOjAwWiJ9LHsiY3JlYXRlZCI6IjAwMDEtMDEtMDFUMDA6MDA6MDBaIn0seyJjcmVhdGVkIjoiMDAwMS0wMS0wMVQwMDowMDowMFoifSx7ImNyZWF0ZWQiOiIwMDAxLTAxLTAxVDAwOjAwOjAwWiJ9LHsiY3JlYXRlZCI6IjAwMDEtMDEtMDFUMDA6MDA6MDBaIn0seyJjcmVhdGVkIjoiMDAwMS0wMS0wMVQwMDowMDowMFoifSx7ImNyZWF0ZWQiOiIwMDAxLTAxLTAxVDAwOjAwOjAwWiJ9LHsiY3JlYXRlZCI6IjAwMDEtMDEtMDFUMDA6MDA6MDBaIn0seyJjcmVhdGVkIjoiMjAyNS0wOS0yNFQxNTo1MToxMy45Mzk0MzQxNjdaIiwiY3JlYXRlZF9ieSI6IkFSRyBSRUxFQVNFX1ZFUlNJT049NC4xLjAiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI1LTA5LTI0VDE1OjUxOjEzLjkzOTQzNDE2N1oiLCJjcmVhdGVkX2J5IjoiRU5WIEZMVUVOVF9CSVRfVkVSU0lPTj00LjEuMCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjUtMDktMjRUMTU6NTE6MTMuOTM5NDM0MTY3WiIsImNyZWF0ZWRfYnkiOiJMQUJFTCBkZXNjcmlwdGlvbj1GbHVlbnQgQml0IG11bHRpLWFyY2hpdGVjdHVyZSBjb250YWluZXIgaW1hZ2UgdmVuZG9yPUZsdWVudCBPcmdhbml6YXRpb24gdmVyc2lvbj00LjEuMCBhdXRob3I9RWR1YXJkbyBTaWx2YSBcdTAwM2NlZHVhcmRvLnNpbHZhQGNocm9ub3NwaGVyZS5pb1x1MDAzZSBvcmcub3BlbmNvbnRhaW5lcnMuaW1hZ2UuZGVzY3JpcHRpb249Rmx1ZW50IEJpdCBjb250YWluZXIgaW1hZ2Ugb3JnLm9wZW5jb250YWluZXJzLmltYWdlLnRpdGxlPUZsdWVudCBCaXQgb3JnLm9wZW5jb250YWluZXJzLmltYWdlLmxpY2Vuc2VzPUFwYWNoZS0yLjAgb3JnLm9wZW5jb250YWluZXJzLmltYWdlLnZlbmRvcj1GbHVlbnQgT3JnYW5pemF0aW9uIG9yZy5vcGVuY29udGFpbmVycy5pbWFnZS52ZXJzaW9uPTQuMS4wIG9yZy5vcGVuY29udGFpbmVycy5pbWFnZS5zb3VyY2U9aHR0cHM6Ly9naXRodWIuY29tL2ZsdWVudC9mbHVlbnQtYml0IG9yZy5vcGVuY29udGFpbmVycy5pbWFnZS5kb2N1bWVudGF0aW9uPWh0dHBzOi8vZG9jcy5mbHVlbnRiaXQuaW8vIG9yZy5vcGVuY29udGFpbmVycy5pbWFnZS5hdXRob3JzPUVkdWFyZG8gU2lsdmEgXHUwMDNjZWR1YXJkby5zaWx2YUBjaHJvbm9zcGhlcmUuaW9cdTAwM2UiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI1LTA5LTI0VDE1OjUxOjEzLjkzOTQzNDE2N1oiLCJjcmVhdGVkX2J5IjoiQ09QWSAvZHBrZyAvICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9LHsiY3JlYXRlZCI6IjIwMjUtMDktMjRUMTU6NTU6NDcuOTY4MzY0MjE0WiIsImNyZWF0ZWRfYnkiOiJDT1BZIC9ldGMvc3NsL2NlcnRzIC9ldGMvc3NsL2NlcnRzICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9LHsiY3JlYXRlZCI6IjIwMjUtMDktMjRUMTU6NTU6NDguMDQ4MjQwMzg3WiIsImNyZWF0ZWRfYnkiOiJDT1BZIC9mbHVlbnQtYml0IC9mbHVlbnQtYml0ICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9LHsiY3JlYXRlZCI6IjIwMjUtMDktMjRUMTU6NTU6NDguMDQ4MjQwMzg3WiIsImNyZWF0ZWRfYnkiOiJFWFBPU0UgXHUwMDI2e1t7ezIwNSAwfSB7MjA1IDB9fV0gMHhjMDAwMzllNmMwfSIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjUtMDktMjRUMTU6NTU6NDguMDQ4MjQwMzg3WiIsImNyZWF0ZWRfYnkiOiJFTlRSWVBPSU5UIFtcIi9mbHVlbnQtYml0L2Jpbi9mbHVlbnQtYml0XCJdIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNS0wOS0yNFQxNTo1NTo0OC4wNDgyNDAzODdaIiwiY3JlYXRlZF9ieSI6IkNNRCBbXCIvZmx1ZW50LWJpdC9iaW4vZmx1ZW50LWJpdFwiIFwiLWNcIiBcIi9mbHVlbnQtYml0L2V0Yy9mbHVlbnQtYml0LmNvbmZcIl0iLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfV0sIm9zIjoibGludXgiLCJyb290ZnMiOnsidHlwZSI6ImxheWVycyIsImRpZmZfaWRzIjpbInNoYTI1NjpiZmY3ZjdhOWQ0NDM1NmQ4Nzg0NTAwMzY2MDk0YzY2Mzk5YWE2YTJlZGQ5OTBjYzcwZTAyZTI3Yzg0NDAyNzUzIiwic2hhMjU2OjhmYTEwYzAxOTRkZjliN2MwNTRjOTBkYmU0ODI1ODVmNzY4YTU0NDI4ZmM5MGE1Yjc4YTAwNjZhMTIzYjFiYmEiLCJzaGEyNTY6NDg0MGM3YzU0MDIzYzg2N2YxOTU2NDQyOWM4OWRkYWU0ZTk1ODljODNkY2U4MjQ5MjE4M2E3ZTlmN2RhYjFmYSIsInNoYTI1NjoxMTRkZGUwZmVmZWJiY2ExMzE2NWQwZGE5YzUwMGE2NjE5MGU0OTdhODJhNTNkY2FhYmMzMTcyZDYzMGJlMWU5Iiwic2hhMjU2OjRkMDQ5ZjgzZDljZjIxZDFmNWNjMGUxMWRlYWYzNmRmMDI3OTBkMGU2MGMxYTM4Mjk1MzhmYjRiNjE2ODUzNjgiLCJzaGEyNTY6YWY1YWE5N2ViZTZjZTE2MDQ3NDdlYzFlMjFhZjcxMzZkZWQzOTFiY2FiZTRhY2VmODgyZTcxOGE4N2M4NmJjYyIsInNoYTI1Njo2ZjFjZGNlYjZhMzE0NmYwY2NiOTg2NTIxMTU2YmVmOGE0MjJjZGJiMDg2MzM5NmY3Zjc1MWY1NzViYTMwOGY0Iiwic2hhMjU2OmJiYjZjYWNiOGM4MmU0ZGE0ZTgxNDNlMDMzNTFlOTM5ZWFiNWUyMWNlMGVmMzMzYzQyZTYzN2FmODZjNTIxN2IiLCJzaGEyNTY6MmE5MmQ2YWM5ZTRmY2MyNzRkNTE2OGIyMTdjYTQ0NThhOWZlYzZmMDk0ZWFkNjhkOTljNzcwNzNmMDhjYWFjMSIsInNoYTI1NjoxYTczYjU0ZjU1NmI0NzdmMGE4YjkzOWQxM2M1MDRhM2I0ZjRkYjcxZjdhMDljNjNhZmJjMTBhY2IzZGU1ODQ5Iiwic2hhMjU2OmY0YWVlOWU1M2M0MmEyMmVkODI0NTEyMThjM2VhMDNkMWVlYThkNmNhOGZiZThlYjRlOTUwMzA0YmE4YThiYjMiLCJzaGEyNTY6YmZlOTEzN2ExYjA0NGU4MDk3Y2RmY2I2ODk5MTM3YThhOTg0ZWQ3MDkzMWVkMWU4ZWYwY2Y3ZTAyM2ExMzlmYyIsInNoYTI1NjpiZDI5NTAyYWRmMTk5YWQ5YzAzYWZiYTliYzc5ZGY1NzJhMjZlYzYwYTJhNmZmZGRhNDg4M2E1YjdhMTYzMmZlIiwic2hhMjU2OjJlNDk4M2M3NjFjZTQ5MzNlY2VjMjNjMzExNzNmZWQ1NTFhMjM3YzhkMGJhMzU5YjY5N2RlNjRiZDk1M2E3YzMiLCJzaGEyNTY6NzA5NTQxMjQxN2QyZGNlMjg5Yjc3ZjdhOGM2MzJhMDdjODJiNzA3ZmU0M2NmZWY3MzY4YzNiNjVjOGQyNTM4YSIsInNoYTI1NjoyNDAxYzVlYTMyYTc1NDUyYmM0YjAyYTY2NGM4MGNmNjNmMTk3NzA0NjUzOTI2ZmNhMTllMjJlNmNiYzg1NjUyIiwic2hhMjU2OjY4MTlhMWFmMDk3ZGY1NDNkNThkYzMwYjUxZjczN2U1NWYzZjQyYTlhMDRlNjQxZjE3NTgzNGE1NWJmMDYyOWMiLCJzaGEyNTY6YzNhYmFlNDQyMzY4ZGM0NDdmMTVjNDY4OTMzODQzYzM2MWYyMjdmNWQ4N2IyYmI4NjUxNWI0OWY0MDU4M2VkOSIsInNoYTI1Njo4NmZhMjY0OTc4NmNjMDkyNWMwMDM0YWRhZjNhZTI4NjYyNjM4MmE1MGI0MzFjMjlhMzg5NmFmOTFmZDAxM2U4Iiwic2hhMjU2OjljZmRiZjA4NTMyNzEwYzNkYWJkODE5MzEwYTQ3ZGQ2ZGNjYTAxOTA0ZjY0YzFmMjNkOTE3Zjc0MjIxNTFjM2IiLCJzaGEyNTY6MGYzNTkwYzc2ZTkxZWUwMmFjZjMwNWJkY2ZmMmY5ODFiYzlmNzgzMDcwNTI0MzgyMDI4ZjA3MWU4ZGEzNmQ4NiJdfX0=",
      "repoDigests": [
        "ghcr.io/fluent/fluent-bit@sha256:4d2d8b84bb33b1a641ecd03904c4c610ce374819546cc175bf88025a1c1683e2"
      ],
      "architecture": "amd64",
      "os": "linux",
      "labels": {
        "author": "Eduardo Silva <eduardo.silva@chronosphere.io>",
        "description": "Fluent Bit multi-architecture container image",
        "org.opencontainers.image.authors": "Eduardo Silva <eduardo.silva@chronosphere.io>",
        "org.opencontainers.image.description": "Fluent Bit container image",
        "org.opencontainers.image.documentation": "https://docs.fluentbit.io/",
        "org.opencontainers.image.licenses": "Apache-2.0",
        "org.opencontainers.image.source": "https://github.com/fluent/fluent-bit",
        "org.opencontainers.image.title": "Fluent Bit",
        "org.opencontainers.image.vendor": "Fluent Organization",
        "org.opencontainers.image.version": "4.1.0",
        "vendor": "Fluent Organization",
        "version": "4.1.0"
      }
    }
  },
  "distro": {
    "name": "debian",
    "version": "12",
    "idLike": []
  },
  "descriptor": {
    "name": "grype",
    "version": "0.116.1",
    "configuration": {
      "output": [
        "json"
      ],
      "file": "agent/security/oss/grype-4.1.0.json",
      "pretty": true,
      "distro": "",
      "add-cpes-if-none": false,
      "output-template-file": "",
      "check-for-app-update": true,
      "only-fixed": false,
      "only-notfixed": false,
      "ignore-wontfix": "",
      "platform": "",
      "search": {
        "scope": "squashed",
        "unindexed-archives": false,
        "indexed-archives": true
      },
      "ignore": [
        {
          "vulnerability": "",
          "include-aliases": false,
          "reason": "",
          "namespace": "",
          "fix-state": "",
          "package": {
            "name": "kernel-headers",
            "version": "",
            "language": "",
            "type": "rpm",
            "location": "",
            "upstream-name": "kernel"
          },
          "vex-status": "",
          "vex-justification": "",
          "match-type": "exact-indirect-match"
        },
        {
          "vulnerability": "",
          "include-aliases": false,
          "reason": "",
          "namespace": "",
          "fix-state": "",
          "package": {
            "name": "linux(-.*)?-headers-.*",
            "version": "",
            "language": "",
            "type": "deb",
            "location": "",
            "upstream-name": "linux.*"
          },
          "vex-status": "",
          "vex-justification": "",
          "match-type": "exact-indirect-match"
        },
        {
          "vulnerability": "",
          "include-aliases": false,
          "reason": "",
          "namespace": "",
          "fix-state": "",
          "package": {
            "name": "linux-libc-dev",
            "version": "",
            "language": "",
            "type": "deb",
            "location": "",
            "upstream-name": "linux"
          },
          "vex-status": "",
          "vex-justification": "",
          "match-type": "exact-indirect-match"
        },
        {
          "vulnerability": "",
          "include-aliases": false,
          "reason": "",
          "namespace": "",
          "fix-state": "",
          "package": {
            "name": "linux-kbuild-.*",
            "version": "",
            "language": "",
            "type": "deb",
            "location": "",
            "upstream-name": "linux.*"
          },
          "vex-status": "",
          "vex-justification": "",
          "match-type": "exact-indirect-match"
        }
      ],
      "exclude": [],
      "externalSources": {
        "enable": false,
        "maven": {
          "searchUpstreamBySha1": true,
          "baseUrl": "https://search.maven.org/solrsearch/select",
          "rateLimit": 300000000
        }
      },
      "match": {
        "java": {
          "using-cpes": false
        },
        "jvm": {
          "using-cpes": true
        },
        "dotnet": {
          "using-cpes": false
        },
        "golang": {
          "using-cpes": false,
          "always-use-cpe-for-stdlib": false,
          "allow-main-module-pseudo-version-comparison": false
        },
        "javascript": {
          "using-cpes": false
        },
        "python": {
          "using-cpes": false
        },
        "ruby": {
          "using-cpes": false
        },
        "rust": {
          "using-cpes": false
        },
        "hex": {
          "using-cpes": false
        },
        "stock": {
          "using-cpes": true
        },
        "dpkg": {
          "using-cpes": false,
          "missing-epoch-strategy": "zero",
          "use-cpes-for-eol": false
        },
        "rpm": {
          "using-cpes": false,
          "missing-epoch-strategy": "auto",
          "use-cpes-for-eol": false
        }
      },
      "fail-on-severity": "",
      "registry": {
        "insecure-skip-tls-verify": false,
        "insecure-use-http": false,
        "ca-cert": ""
      },
      "show-suppressed": false,
      "by-cve": false,
      "SortBy": {
        "sort-by": "risk"
      },
      "name": "",
      "default-image-pull-source": "",
      "from": null,
      "vex-documents": [],
      "vex-add": [],
      "match-upstream-kernel-headers": false,
      "fix-channel": {
        "redhat-eus": {
          "apply": "auto",
          "versions": ">= 8.0"
        },
        "ubuntu-esm": {
          "apply": "auto",
          "versions": ""
        }
      },
      "timestamp": false,
      "alerts": {
        "enable-eol-distro-warnings": true
      },
      "db": {
        "cache-dir": ".cache/grype/db",
        "update-url": "https://grype.anchore.io/databases",
        "ca-cert": "",
        "auto-update": true,
        "validate-by-hash-on-start": true,
        "validate-age": true,
        "max-allowed-built-age": 432000000000000,
        "require-update-check": false,
        "update-available-timeout": 30000000000,
        "update-download-timeout": 300000000000,
        "max-update-check-frequency": 7200000000000
      },
      "exp": {},
      "dev": {
        "db": {
          "debug": false
        }
      }
    },
    "db": {
      "status": {
        "schemaVersion": "v6.1.9",
        "from": "https://grype.anchore.io/databases/v6/vulnerability-db_v6.1.9_2026-07-29T00:35:30Z_1785308909.tar.zst?checksum=sha256%3Aea7bc3b89f29dfd4e8b10c12532caefb76f3df0bf55f604015b376cda3ed1275",
        "built": "2026-07-29T07:08:29Z",
        "path": ".cache/grype/db/6/vulnerability.db",
        "valid": true
      },
      "providers": {
        "alma": {
          "captured": "2026-07-29T00:35:30Z",
          "input": "xxh64:abb7063a7ba65fb4"
        },
        "alpine": {
          "captured": "2026-07-29T00:36:07Z",
          "input": "xxh64:8798fcdf7f914d8d"
        },
        "amazon": {
          "captured": "2026-07-29T00:36:01Z",
          "input": "xxh64:88a758ce5375f610"
        },
        "arch": {
          "captured": "2026-07-29T00:35:34Z",
          "input": "xxh64:520eab44f4a7afb9"
        },
        "bitnami": {
          "captured": "2026-07-29T00:35:48Z",
          "input": "xxh64:63ce2c93153534d1"
        },
        "chainguard": {
          "captured": "2026-07-29T00:35:39Z",
          "input": "xxh64:f21a3533886948ac"
        },
        "chainguard-libraries": {
          "captured": "2026-07-29T00:35:54Z",
          "input": "xxh64:51db172885e7d64c"
        },
        "debian": {
          "captured": "2026-07-29T00:35:40Z",
          "input": "xxh64:caafcd86e2756a35"
        },
        "echo": {
          "captured": "2026-07-29T00:35:31Z",
          "input": "xxh64:dd294ce1f17a8013"
        },
        "eol": {
          "captured": "2026-07-29T00:35:38Z",
          "input": "xxh64:847f46f09d7c4023"
        },
        "epss": {
          "captured": "2026-07-29T00:35:42Z",
          "input": "xxh64:00f000e915b52fde"
        },
        "fedora": {
          "captured": "2026-07-29T00:36:00Z",
          "input": "xxh64:ed2db138a968c477"
        },
        "github": {
          "captured": "2026-07-29T00:35:35Z",
          "input": "xxh64:4cda0a6108cedacd"
        },
        "govulndb": {
          "captured": "2026-07-29T00:35:39Z",
          "input": "xxh64:0a46e3a1eb9133d7"
        },
        "hummingbird": {
          "captured": "2026-07-29T00:37:24Z",
          "input": "xxh64:007e54f1d2374656"
        },
        "kev": {
          "captured": "2026-07-29T00:36:10Z",
          "input": "xxh64:b277e74875e2d7e7"
        },
        "mariner": {
          "captured": "2026-07-29T00:35:59Z",
          "input": "xxh64:118dde1bfa7425bc"
        },
        "minimos": {
          "captured": "2026-07-29T00:35:39Z",
          "input": "xxh64:d2790bd83cb9ab02"
        },
        "nvd": {
          "captured": "2026-07-29T00:36:37Z",
          "input": "xxh64:e2ced04648ebf499"
        },
        "oracle": {
          "captured": "2026-07-29T00:36:54Z",
          "input": "xxh64:44433375be8c9a34"
        },
        "photon": {
          "captured": "2026-07-29T00:36:43Z",
          "input": "xxh64:d76f906da09cb879"
        },
        "rhel": {
          "captured": "2026-07-29T00:36:51Z",
          "input": "xxh64:65732be4e1a2ab89"
        },
        "secureos": {
          "captured": "2026-07-29T00:35:41Z",
          "input": "xxh64:e6c0fc8dff733a0c"
        },
        "sles": {
          "captured": "2026-07-29T00:36:10Z",
          "input": "xxh64:1c10d2c3c28399e7"
        },
        "ubuntu": {
          "captured": "2026-07-29T00:41:24Z",
          "input": "xxh64:2e4b9d5c5894afac"
        },
        "wolfi": {
          "captured": "2026-07-29T00:35:51Z",
          "input": "xxh64:aa89ce46df8f030f"
        }
      }
    }
  }
}
