{"resultsPerPage":166,"startIndex":0,"totalResults":166,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-31T21:20:54.322","vulnerabilities":[{"cve":{"id":"CVE-2013-0335","sourceIdentifier":"secalert@redhat.com","published":"2013-03-22T21:55:00.880","lastModified":"2026-07-31T15:16:24.803","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port."},{"lang":"es","value":"OpenStack Compute (Nova) Grizzly, Folsom (v2012.2) y Essex (v2012.1) permite a usuarios remotos autenticados acceder a una máquina virtual en circunstancias oportunistas utilizando el token VNC para eliminar una máquina virtual que se dirigía al mismo puerto VNC."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"OpenStack Folsom for RHEL 6","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openstack-nova","cpes":["cpe:/a:redhat:openstack:2::el6"],"versions":[{"version":"0:2012.2.3-7.el6ost","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 13 (Queens)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-user-workloads/openstack-nova-compute","cpes":["cpe:/a:redhat:openstack:13"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 13 (Queens)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-user-workloads/openstack-nova-compute-ironic","cpes":["cpe:/a:redhat:openstack:13"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 16.2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-user-workloads/openstack-nova-compute","cpes":["cpe:/a:redhat:openstack:16.2"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 16.2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-user-workloads/openstack-nova-compute-ironic","cpes":["cpe:/a:redhat:openstack:16.2"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-user-workloads/openstack-nova-compute","cpes":["cpe:/a:redhat:openstack:17.1"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-user-workloads/openstack-nova-compute-ironic","cpes":["cpe:/a:redhat:openstack:17.1"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 18.0","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-user-workloads/openstack-nova-compute","cpes":["cpe:/a:redhat:openstack:18.0"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":4.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6.0,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Primary","description":[{"lang":"en","value":"CWE-613"}]},{"source":"nvd@nist.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-264"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:essex:2012.1:*:*:*:*:*:*:*","matchCriteriaId":"E5FDB43F-B315-4F68-9D86-B644F2D4DF9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:folsom:2012.2:*:*:*:*:*:*:*","matchCriteriaId":"E76B76AB-D744-4163-8615-7BA18ABB1347"},{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:grizzly:2012.2:*:*:*:*:*:*:*","matchCriteriaId":"C1D5C8DE-FC66-4787-A65B-CA921881DF67"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*","matchCriteriaId":"E4174F4F-149E-41A6-BBCC-D01114C05F38"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*","matchCriteriaId":"F5D324C4-97C7-49D3-A809-9EAD4B690C69"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*","matchCriteriaId":"E2076871-2E80-4605-A470-A41C1A8EC7EE"}]}]}],"references":[{"url":"http://rhn.redhat.com/errata/RHSA-2013-0709.html","source":"secalert@redhat.com"},{"url":"http://secunia.com/advisories/52337","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"http://secunia.com/advisories/52728","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2013/02/26/7","source":"secalert@redhat.com"},{"url":"http://www.osvdb.org/90657","source":"secalert@redhat.com"},{"url":"http://www.ubuntu.com/usn/USN-1771-1","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2013:0709","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2013-0335","source":"secalert@redhat.com"},{"url":"https://bugs.launchpad.net/nova/+bug/1125378","source":"secalert@redhat.com"},{"url":"https://github.com/advisories/GHSA-qfp8-hfqx-c79c","source":"secalert@redhat.com"},{"url":"https://review.openstack.org/#/c/22086/","source":"secalert@redhat.com"},{"url":"https://review.openstack.org/#/c/22758","source":"secalert@redhat.com"},{"url":"https://review.openstack.org/#/c/22872/","source":"secalert@redhat.com"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-0709.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/52337","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://secunia.com/advisories/52728","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2013/02/26/7","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.osvdb.org/90657","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.ubuntu.com/usn/USN-1771-1","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugs.launchpad.net/nova/+bug/1125378","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://review.openstack.org/#/c/22086/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://review.openstack.org/#/c/22758","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://review.openstack.org/#/c/22872/","source":"af854a3a-2127-422b-91ae-364da2661108"}],"evaluatorImpact":"Per http://www.ubuntu.com/usn/USN-1771-1/\r\n\"A security issue affects these releases of Ubuntu and its derivatives:\r\n\r\nUbuntu 12.10\r\nUbuntu 12.04 LTS\r\nUbuntu 11.10\""}},{"cve":{"id":"CVE-2023-6507","sourceIdentifier":"cna@python.org","published":"2023-12-08T19:15:08.440","lastModified":"2026-07-31T15:16:26.330","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases.\n\nWhen using the `extra_groups=` parameter with an empty list as a value (ie `extra_groups=[]`) the logic regressed to not call `setgroups(0, NULL)` before calling `exec()`, thus not dropping the original processes' groups before starting the new process. There is no issue when the parameter isn't used or when any value is used besides an empty list.\n\nThis issue only impacts CPython processes run with sufficient privilege to make the `setgroups` system call (typically `root`)."},{"lang":"es","value":"Se encontró un problema en el módulo `subproceso` de CPython 3.12.0 en plataformas POSIX. El problema se solucionó en CPython 3.12.1 y no afecta a otras versiones estables. Cuando se utiliza el parámetro `extra_groups=` con una lista vacía como valor (es decir, `extra_groups=[]`), la lógica retrocede para no llamar a `setgroups(0, NULL)` antes de llamar a `exec()`, por lo que no se descarta el grupos de procesos originales antes de iniciar el nuevo proceso. No hay ningún problema cuando no se usa el parámetro o cuando se usa cualquier valor además de una lista vacía. Este problema solo afecta los procesos de CPython que se ejecutan con privilegios suficientes para realizar la llamada al sistema \"setgroups\" (normalmente \"root\")."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","platforms":["POSIX"],"repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.12.1","versionType":"python","status":"affected"},{"version":"3.13.0a1","lessThan":"3.13.0a3","versionType":"python","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"python","product":"cpython","defaultStatus":"unknown","cpes":["cpe:2.3:a:python:cpython:3.13.0:*:*:*:*:*:*:*"],"versions":[{"version":"3.13.0","status":"affected"}]},{"vendor":"python","product":"cpython","defaultStatus":"unknown","cpes":["cpe:2.3:a:python:cpython:*:*:*:*:*:*:*:*"],"versions":[{"version":"3.12.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-01-31T20:16:20.207522Z","id":"CVE-2023-6507","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-269"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:3.12.0:-:*:*:*:*:*:*","matchCriteriaId":"5C76EDC2-43FF-448B-B65C-20AC83D680FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:3.13.0:alpha1:*:*:*:*:*:*","matchCriteriaId":"978582FF-B8F3-479F-AE77-359E9AEE6F23"},{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:3.13.0:alpha2:*:*:*:*:*:*","matchCriteriaId":"84E3F62C-7218-4DC3-8473-8A576739643A"}]}]}],"references":[{"url":"https://github.com/python/cpython/commit/10e9bb13b8dcaa414645b9bd10718d8f7179e82b","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/85bbfa8a4bbdbb61a3a84fbd7cb29a4096ab8a06","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9fe7655c6ce0b8e9adc229daf681b6d30e6b1610","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/112334","source":"cna@python.org","tags":["Issue Tracking","Patch"]},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/AUL7QFHBLILGISS7U63B47AYSSGJJQZD/","source":"cna@python.org","tags":["Third Party Advisory"]},{"url":"https://github.com/python/cpython/commit/10e9bb13b8dcaa414645b9bd10718d8f7179e82b","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/python/cpython/commit/85bbfa8a4bbdbb61a3a84fbd7cb29a4096ab8a06","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/python/cpython/commit/9fe7655c6ce0b8e9adc229daf681b6d30e6b1610","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/python/cpython/issues/112334","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch"]},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/AUL7QFHBLILGISS7U63B47AYSSGJJQZD/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2024-5642","sourceIdentifier":"cna@python.org","published":"2024-06-27T21:15:16.070","lastModified":"2026-07-31T15:16:26.997","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"CPython 3.9 and earlier doesn't disallow configuring an empty list (\"[]\") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see CVE-2024-5535 for OpenSSL). This vulnerability is of low severity due to NPN being not widely used and specifying an empty list likely being uncommon in-practice (typically a protocol name would be configured)."},{"lang":"es","value":"CPython 3.9 y versiones anteriores no permiten la configuración de una lista vacía (\"[]\") para SSLContext.set_npn_protocols(), que es un valor no válido para la API OpenSSL subyacente. Esto da como resultado una lectura excesiva del búfer cuando se utiliza NPN (consulte CVE-2024-5535 para OpenSSL). Esta vulnerabilidad es de baja gravedad debido a que NPN no se usa ampliamente y especificar una lista vacía probablemente sea poco común en la práctica (normalmente se configuraría un nombre de protocolo)."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.24","versionType":"python","status":"affected"},{"version":"3.10.0a1","lessThan":"3.10.0b1","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-28T13:47:34.169947Z","id":"CVE-2024-5642","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"references":[{"url":"http://www.openwall.com/lists/oss-security/2024/06/28/4","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/39258d3595300bc7b952854c915f63ae2d4b9c3e","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/a2cdbb6e8188ba9ba8b356b28d91bff60e86fe31","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/121227","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/23014","source":"cna@python.org"},{"url":"https://jbp.io/2024/06/27/cve-2024-5535-openssl-memory-safety.html","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/PLP2JI3PJY33YG6P5BZYSSNU66HASXBQ/","source":"cna@python.org"},{"url":"https://security.netapp.com/advisory/ntap-20240726-0005/","source":"cna@python.org"},{"url":"http://www.openwall.com/lists/oss-security/2024/06/28/4","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/python/cpython/commit/39258d3595300bc7b952854c915f63ae2d4b9c3e","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/python/cpython/issues/121227","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/python/cpython/pull/23014","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://jbp.io/2024/06/27/cve-2024-5535-openssl-memory-safety.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/PLP2JI3PJY33YG6P5BZYSSNU66HASXBQ/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20240726-0005/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-12254","sourceIdentifier":"cna@python.org","published":"2024-12-06T16:15:20.623","lastModified":"2026-07-31T15:16:26.553","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()\n method would not \"pause\" writing and signal to the Protocol to drain \nthe buffer to the wire once the write buffer reached the \"high-water \nmark\". Because of this, Protocols would not periodically drain the write\n buffer potentially leading to memory exhaustion.\n\n\n\n\n\nThis\n vulnerability likely impacts a small number of users, you must be using\n Python 3.12.0 or later, on macOS or Linux, using the asyncio module \nwith protocols, and using .writelines() method which had new \nzero-copy-on-write behavior in Python 3.12.0 and later. If not all of \nthese factors are true then your usage of Python is unaffected."},{"lang":"es","value":"Starting de Python 3.12.0, el método asyncio._SelectorSocketTransport.writelines() no \"pausaba\" la escritura ni enviaba señales al protocolo para que vaciara el búfer hacia el cable una vez que el búfer de escritura alcanzaba el \"límite superior\". Debido a esto, los protocolos no vaciaban periódicamente el búfer de escritura, lo que podría provocar el agotamiento de la memoria. Es probable que esta vulnerabilidad afecte a una pequeña cantidad de usuarios. Debes usar Python 3.12.0 o posterior, en macOS o Linux, usar el módulo asyncio con protocolos y usar el método .writelines(), que tenía un nuevo comportamiento de copia cero al escribir en Python 3.12.0 y posterior. Si no se cumplen todos estos factores, tu uso de Python no se ve afectado."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","modules":["asyncio"],"platforms":["MacOS","Linux"],"repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.12.9","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.2","versionType":"python","status":"affected"},{"version":"3.14.0a1","lessThan":"3.14.0a3","versionType":"python","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"python_software_foundation","product":"cpython","defaultStatus":"unknown","cpes":["cpe:2.3:a:python_software_foundation:cpython:*:*:*:*:*:*:*:*"],"versions":[{"version":"3.12.0","lessThan":"3.14.0a1","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-06T15:35:11.234951Z","id":"CVE-2024-12254","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-400"},{"lang":"en","value":"CWE-770"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://github.com/python/cpython/commit/71e8429ac8e2adc10084ab5ec29a62f4b6671a82","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9aa0deb2eef2655a1029ba228527b152353135b5","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/e991ac8f2037d78140e417cc9a9486223eb3e786","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/127655","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/127656","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/H4O3UBAOAQQXGT4RE3E4XQYR5XLROORB/","source":"cna@python.org"},{"url":"http://www.openwall.com/lists/oss-security/2024/12/06/1","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20250404-0010/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2025-0938","sourceIdentifier":"cna@python.org","published":"2025-01-31T18:15:38.053","lastModified":"2026-07-31T14:16:42.597","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers."},{"lang":"es","value":"Las funciones estándar librería de Python `urllib.parse.urlsplit` y `urlparse` aceptaban nombres de dominio que incluían corchetes, lo que no es válido según RFC 3986. Los corchetes solo se deben usar como delimitadores para especificar hosts IPv6 e IPvFuture en las URL. Esto podría generar un análisis diferencial entre el analizador de URL de Python y otros analizadores de URL que cumplen con las especificaciones."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.22","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.17","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.12","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.9","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.2","versionType":"python","status":"affected"},{"version":"3.14.0a1","lessThan":"3.14.0a5","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-31T18:50:16.654297Z","id":"CVE-2025-0938","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://github.com/python/cpython/commit/526617ed68cde460236c973e5d0a8bad4de896ba","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/90e526ae67b172ed7c6c56e7edad36263b0f9403","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/a7084f6075c9595ba60119ce8c62f1496f50c568","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/b8b4b713c5f8ec0958c7ef8d29d6711889bc94ab","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/d89a5f6a6e65511a5f6e0618c4c30a7aa5aba56a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/ff4e5c25666f63544071a6b075ae8b25c98b7a32","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/105704","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/129418","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/K4EUG6EKV6JYFIC24BASYOZS4M5XOQIB/","source":"cna@python.org"},{"url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20250314-0002/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2025-1795","sourceIdentifier":"cna@python.org","published":"2025-02-28T19:15:36.550","lastModified":"2026-07-31T14:16:44.000","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers."},{"lang":"es","value":"Durante el plegado de una lista de direcciones, cuando una coma separadora termina en una línea plegada y esa línea debe codificarse en Unicode, entonces el separador en sí también se codifica en Unicode. El comportamiento esperado es que la coma separadora siga siendo una coma de plan. Esto puede provocar que algunos servidores de correo interpreten mal el encabezado de la dirección."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","modules":["email"],"repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.23","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.17","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.9","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.3","versionType":"python","status":"affected"},{"version":"3.13.0a1","lessThan":"3.13.0a5","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.3,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-28T20:30:47.670593Z","id":"CVE-2025-1795","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-116"}]}],"references":[{"url":"https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/a4ef689ce670684ec132204b1cd03720c8e0a03d","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/d4df3c55e4c5513947f907f24766b34d2ae8c090","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/100884","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/100885","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/119099","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/","source":"cna@python.org"},{"url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2025-4516","sourceIdentifier":"cna@python.org","published":"2025-05-15T14:15:31.753","lastModified":"2026-07-31T14:16:44.797","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"There is an issue in CPython when using `bytes.decode(\"unicode_escape\", error=\"ignore|replace\")`. If you are not using the \"unicode_escape\" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError."},{"lang":"es","value":"Hay un problema en CPython al usar `bytes.decode(\"unicode_escape\", error=\"ignore|replace\")`. Si no usa la codificación \"unicode_escape\" ni un controlador de errores, su uso no se ve afectado. Para solucionar este problema, puede dejar de usar el controlador `error=` y, en su lugar, encapsular la llamada `bytes.decode()` en un `try-except` que capture el `DecodeError`."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.23","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.18","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.13","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.11","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.4","versionType":"python","status":"affected"},{"version":"3.14.0a1","lessThan":"3.14.0b2","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-15T14:18:44.612125Z","id":"CVE-2025-4516","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"references":[{"url":"https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/133767","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/129648","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/","source":"cna@python.org"},{"url":"http://www.openwall.com/lists/oss-security/2025/05/16/4","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2025/05/19/1","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2024-12718","sourceIdentifier":"cna@python.org","published":"2025-06-03T13:15:20.183","lastModified":"2026-07-31T15:16:26.800","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Allows modifying some file metadata (e.g. last modified) with filter=\"data\" or file permissions (chmod) with filter=\"tar\" of files outside the extraction directory.\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."},{"lang":"es","value":"Permite modificar algunos metadatos de archivo (p. ej., la última modificación) con filter=\"data\" o permisos de archivo (chmod) con filter=\"tar\" de archivos fuera del directorio de extracción. Esta vulnerabilidad afecta al usar el módulo tarfile para extraer archivos tar no confiables mediante TarFile.extractall() o TarFile.extract() y el parámetro filter= con el valor \"data\" o \"tar\". Consulte la documentación sobre filtros de extracción de archivos tar (https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter) para obtener más información. Estas vulnerabilidades solo afectan a las versiones de Python 3.12 o posteriores; las versiones anteriores no incluyen la función de filtro de extracción. Tenga en cuenta que para Python 3.14 o posteriores, el valor predeterminado de filter= cambió de \"sin filtrado\" a \"data\", por lo que si utiliza este nuevo comportamiento predeterminado, su uso también se verá afectado. Tenga en cuenta que ninguna de estas vulnerabilidades afecta significativamente la instalación de distribuciones fuente que son archivos tar, ya que estas permiten la ejecución de código arbitrario durante el proceso de compilación. Sin embargo, al evaluar distribuciones fuente, es importante evitar instalar distribuciones fuente con enlaces sospechosos."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.23","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.18","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.13","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.11","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.4","versionType":"python","status":"affected"},{"version":"3.14.0a1","lessThan":"3.14.0b3","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-24T15:57:41.217375Z","id":"CVE-2024-12718","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/127987","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/135034","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/135037","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/127987","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2025-4138","sourceIdentifier":"cna@python.org","published":"2025-06-03T13:15:20.377","lastModified":"2026-07-31T14:16:44.240","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."},{"lang":"es","value":"Permite ignorar el filtro de extracción, lo que permite que los enlaces simbólicos apunten fuera del directorio de destino y la modificación de algunos metadatos de archivo. Esta vulnerabilidad afecta al usar el módulo tarfile para extraer archivos tar no confiables mediante TarFile.extractall() o TarFile.extract() y el parámetro filter= con el valor \"data\" o \"tar\". Consulte la documentación sobre filtros de extracción de archivos tar (https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter) para obtener más información. Solo las versiones de Python 3.12 o posteriores se ven afectadas por estas vulnerabilidades; las versiones anteriores no incluyen la función de filtro de extracción. Tenga en cuenta que para Python 3.14 o posteriores, el valor predeterminado de filter= cambió de \"sin filtrado\" a \"data\", por lo que si utiliza este nuevo comportamiento predeterminado, su uso también se verá afectado. Tenga en cuenta que ninguna de estas vulnerabilidades afecta significativamente la instalación de distribuciones de código fuente que sean archivos tar, ya que estas permiten la ejecución de código arbitrario durante el proceso de compilación. Sin embargo, al evaluar distribuciones de origen es importante evitar instalar distribuciones de origen con enlaces sospechosos."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","modules":["tarfile"],"repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.23","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.18","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.13","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.11","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.4","versionType":"python","status":"affected"},{"version":"3.14.0a1","lessThan":"3.14.0b3","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-03T13:29:22.889454Z","id":"CVE-2025-4138","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/135034","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/135037","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/","source":"cna@python.org"}]}},{"cve":{"id":"CVE-2025-4330","sourceIdentifier":"cna@python.org","published":"2025-06-03T13:15:20.503","lastModified":"2026-07-31T14:16:44.480","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."},{"lang":"es","value":"Permite ignorar el filtro de extracción, lo que permite que los enlaces simbólicos apunten fuera del directorio de destino y la modificación de algunos metadatos de archivo. Esta vulnerabilidad afecta al usar el módulo tarfile para extraer archivos tar no confiables mediante TarFile.extractall() o TarFile.extract() y el parámetro filter= con el valor \"data\" o \"tar\". Consulte la documentación sobre filtros de extracción de archivos tar (https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter) para obtener más información. Solo las versiones de Python 3.12 o posteriores se ven afectadas por estas vulnerabilidades; las versiones anteriores no incluyen la función de filtro de extracción. Tenga en cuenta que para Python 3.14 o posteriores, el valor predeterminado de filter= cambió de \"sin filtrado\" a \"data\", por lo que si utiliza este nuevo comportamiento predeterminado, su uso también se verá afectado. Tenga en cuenta que ninguna de estas vulnerabilidades afecta significativamente la instalación de distribuciones de código fuente que sean archivos tar, ya que estas permiten la ejecución de código arbitrario durante el proceso de compilación. Sin embargo, al evaluar distribuciones de origen es importante evitar instalar distribuciones de origen con enlaces sospechosos."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","modules":["tarfile"],"repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.23","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.18","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.13","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.11","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.4","versionType":"python","status":"affected"},{"version":"3.14.0a1","lessThan":"3.14.0b3","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-03T13:27:07.778910Z","id":"CVE-2025-4330","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/135034","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/135037","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/","source":"cna@python.org"}]}},{"cve":{"id":"CVE-2025-4435","sourceIdentifier":"cna@python.org","published":"2025-06-03T13:15:20.630","lastModified":"2026-07-31T14:16:44.653","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped."},{"lang":"es","value":"Al usar TarFile.errorlevel = 0 y extraer con un filtro, el comportamiento documentado es que cualquier miembro filtrado se omite y no se extrae. Sin embargo, el comportamiento real de TarFile.errorlevel = 0 en las versiones afectadas es que el miembro se extrae y no se omite."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","modules":["tarfile"],"repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.23","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.18","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.13","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.11","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.4","versionType":"python","status":"affected"},{"version":"3.14.0a1","lessThan":"3.14.0b3","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-03T13:58:00.099450Z","id":"CVE-2025-4435","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-682"}]}],"references":[{"url":"https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/135034","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/135037","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/","source":"cna@python.org"}]}},{"cve":{"id":"CVE-2025-4517","sourceIdentifier":"cna@python.org","published":"2025-06-03T13:15:20.837","lastModified":"2026-07-31T14:16:44.957","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Allows arbitrary filesystem writes outside the extraction directory during extraction with filter=\"data\".\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."},{"lang":"es","value":"Permite escrituras arbitrarias en el sistema de archivos fuera del directorio de extracción durante la extracción con filter=\"data\". Esta vulnerabilidad afecta al usuario si utiliza el módulo tarfile para extraer archivos tar no confiables mediante TarFile.extractall() o TarFile.extract() y el parámetro filter= con el valor \"data\" o \"tar\". Consulte la documentación sobre filtros de extracción de archivos tar (https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter) para obtener más información. Solo las versiones de Python 3.12 o posteriores se ven afectadas por estas vulnerabilidades; las versiones anteriores no incluyen la función de filtro de extracción. Tenga en cuenta que, para Python 3.14 o posteriores, el valor predeterminado de filter= cambió de \"sin filtrado\" a \"data\", por lo que si utiliza este nuevo comportamiento predeterminado, su uso también se verá afectado. Tenga en cuenta que ninguna de estas vulnerabilidades afecta significativamente la instalación de distribuciones fuente que son archivos tar, ya que estas permiten la ejecución de código arbitrario durante el proceso de compilación. Sin embargo, al evaluar distribuciones de origen es importante evitar instalar distribuciones de origen con enlaces sospechosos."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","modules":["tarfile"],"repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.23","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.18","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.13","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.11","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.4","versionType":"python","status":"affected"},{"version":"3.14.0a1","lessThan":"3.14.0b3","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-24T03:55:18.283911Z","id":"CVE-2025-4517","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/135034","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/135037","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/","source":"cna@python.org"}]}},{"cve":{"id":"CVE-2025-6069","sourceIdentifier":"cna@python.org","published":"2025-06-17T14:15:33.677","lastModified":"2026-07-31T14:16:45.130","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service."},{"lang":"es","value":"La clase html.parser.HTMLParser tenía una complejidad cuadrática en el peor de los casos al procesar ciertas entradas mal formadas que podían llevar a una denegación de servicio amplificada."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","modules":["html.parser"],"repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.24","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.19","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.14","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.12","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.6","versionType":"python","status":"affected"},{"version":"3.14.0a1","lessThan":"3.14.0b3","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-17T13:58:28.646020Z","id":"CVE-2025-6069","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"references":[{"url":"https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fc","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/135462","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/135464","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/","source":"cna@python.org"}]}},{"cve":{"id":"CVE-2025-8194","sourceIdentifier":"cna@python.org","published":"2025-07-28T19:15:43.793","lastModified":"2026-07-31T14:16:45.453","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. \n\nThis vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1"},{"lang":"es","value":"Existe un defecto en el módulo \"tarfile\" de CPython que afecta a las API de extracción y enumeración de entradas de \"TarFile\". La implementación de tar procesaba archivos tar con desplazamientos negativos sin errores, lo que resultaba en un bucle infinito y un bloqueo durante el análisis de archivos tar manipulados con fines maliciosos. Esta vulnerabilidad se puede mitigar incluyendo el siguiente parche después de importar el módulo \"tarfile\": import tarfile def _block_patched(self, count):     if count &lt; 0: # pragma: no cover         raise tarfile.InvalidHeaderError(\"invalid offset\")     return _block_patched._orig_block(self, count) _block_patched._orig_block = tarfile.TarInfo._block tarfile.TarInfo._block = _block_patched"}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.24","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.19","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.14","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.12","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.6","versionType":"python","status":"affected"},{"version":"3.14.0a1","lessThan":"3.14.0rc2","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-28T18:57:54.114655Z","id":"CVE-2025-8194","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-835"}]}],"references":[{"url":"https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/57f5981d6260ed21266e0c26951b8564cc252bc2","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/7040aa54f14676938970e10c5f74ea93cd56aa38","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/73f03e4808206f71eb6b92c579505a220942ef19","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/b4ec17488eedec36d3c05fec127df71c0071f6cb","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/c9d9f78feb1467e73fd29356c040bde1c104f29f","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/cdae923ffe187d6ef916c0f665a31249619193fe","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/130577","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/137027","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/","source":"cna@python.org"},{"url":"http://www.openwall.com/lists/oss-security/2025/07/28/1","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2025/07/28/2","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2025-8291","sourceIdentifier":"cna@python.org","published":"2025-10-07T18:16:00.317","lastModified":"2026-07-31T14:16:45.617","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The 'zipfile' module would not check the validity of the ZIP64 End of\nCentral Directory (EOCD) Locator record offset value would not be used to\nlocate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be\nassumed to be the previous record in the ZIP archive. This could be abused\nto create ZIP archives that are handled differently by the 'zipfile' module\ncompared to other ZIP implementations.\n\n\nRemediation maintains this behavior, but checks that the offset specified\nin the ZIP64 EOCD Locator record matches the expected value."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.24","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.19","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.14","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.12","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.10","versionType":"python","status":"affected"},{"version":"3.14.0","lessThan":"3.14.1","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-29T15:15:06.403842Z","id":"CVE-2025-8291","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-1285"}]}],"references":[{"url":"https://github.com/python/cpython/commit/162997bb70e067668c039700141770687bc8f267","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/1d29afb0d6218aa8fb5e1e4a6133a4778d89bb46","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/333d4a6f4967d3ace91492a39ededbcf3faa76a6","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/76437ac248ad8ca44e9bf697b02b1e2241df2196","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/8392b2f0d35678407d9ce7d95655a5b77de161b4","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/bca11ae7d575d87ed93f5dd6a313be6246e3e388","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/d11e69d6203080e3ec450446bfed0516727b85c3","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/139700","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/139702","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/QECOPWMTH4VPPJAXAH2BGTA4XADOP62G/","source":"cna@python.org"},{"url":"https://github.com/google/security-research/security/advisories/GHSA-hhv7-p4pg-wm6p","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2025-12.json","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2025-6075","sourceIdentifier":"cna@python.org","published":"2025-10-31T17:15:48.693","lastModified":"2026-07-31T14:16:45.270","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"If the value passed to os.path.expandvars() is user-controlled a \nperformance degradation is possible when expanding environment \nvariables."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.9.25","versionType":"python","status":"affected"},{"version":"3.10.0","lessThan":"3.10.20","versionType":"python","status":"affected"},{"version":"3.11.0","lessThan":"3.11.15","versionType":"python","status":"affected"},{"version":"3.12.0","lessThan":"3.12.13","versionType":"python","status":"affected"},{"version":"3.13.0","lessThan":"3.13.10","versionType":"python","status":"affected"},{"version":"3.14.0","lessThan":"3.14.1","versionType":"python","status":"affected"},{"version":"3.15.0a1","lessThan":"3.15.0a2","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":1.8,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-31T17:54:46.289107Z","id":"CVE-2025-6075","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:*:*:*:*:*:*:*:*","versionEndExcluding":"3.9.0","matchCriteriaId":"6E6A50B5-4D36-483E-9326-8D824E197D27"},{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:*:*:*:*:*:*:*:*","versionStartIncluding":"3.13.1","versionEndExcluding":"3.13.11","matchCriteriaId":"16490D75-8319-4FF4-8DB1-94F1722DC561"},{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:*:*:*:*:*:*:*:*","versionStartIncluding":"3.14.0","versionEndExcluding":"3.14.1","matchCriteriaId":"6E66BA7A-987F-4E24-8B69-4F46D6FCD19E"},{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*","matchCriteriaId":"A3327507-0B1D-4F28-A983-D07A2C8A7696"}]}]}],"references":[{"url":"https://github.com/python/cpython/commit/2e6150adccaaf5bd95d4c19dfd04a36e0b325d8c","source":"cna@python.org","tags":["Patch"]},{"url":"https://github.com/python/cpython/commit/5dceb93486176e6b4a6d9754491005113eb23427","source":"cna@python.org","tags":["Patch"]},{"url":"https://github.com/python/cpython/commit/631ba3407e3348ccd56ce5160c4fb2c5dc5f4d84","source":"cna@python.org","tags":["Patch"]},{"url":"https://github.com/python/cpython/commit/892747b4cf0f95ba8beb51c0d0658bfaa381ebca","source":"cna@python.org","tags":["Patch"]},{"url":"https://github.com/python/cpython/commit/9ab89c026aa9611c4b0b67c288b8303a480fe742","source":"cna@python.org","tags":["Patch"]},{"url":"https://github.com/python/cpython/commit/c8a5f3435c342964e0a432cc9fb448b7dbecd1ba","source":"cna@python.org","tags":["Patch"]},{"url":"https://github.com/python/cpython/commit/f029e8db626ddc6e3a3beea4eff511a71aaceb5c","source":"cna@python.org","tags":["Patch"]},{"url":"https://github.com/python/cpython/issues/136065","source":"cna@python.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/IUP5QJ6D4KK6ULHOMPC7DPNKRYQTQNLA/","source":"cna@python.org","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-5713","sourceIdentifier":"cna@python.org","published":"2026-04-14T16:16:48.717","lastModified":"2026-07-31T14:16:50.590","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"The \"profiling.sampling\" module (Python 3.15+) and \"asyncio introspection capabilities\" (3.14+, \"python -m asyncio ps\" and \"python -m asyncio pstree\") features could be used to read and write addresses in a privileged process if that process connected to a malicious or \"infected\" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.14.5","versionType":"python","status":"affected"},{"version":"3.15.0a1","lessThan":"3.15.0b1","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-14T15:49:26.893551Z","id":"CVE-2026-5713","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-121"},{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://github.com/python/cpython/commit/289fd2c97a7e5aecb8b69f94f5e838ccfeee7e67","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/316f6265b7f9ca4ffed5346b747475ef1943f35d","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/148178","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/148187","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/","source":"cna@python.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/04/15/6","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-3298","sourceIdentifier":"cna@python.org","published":"2026-04-21T15:16:37.047","lastModified":"2026-07-31T14:16:50.137","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"The method \"sock_recvfrom_into()\" of \"asyncio.ProacterEventLoop\" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected."}],"affected":[{"source":"cna@python.org","affectedData":[{"vendor":"Python Software Foundation","product":"CPython","defaultStatus":"unaffected","repo":"https://github.com/python/cpython","versions":[{"version":"0","lessThan":"3.13.14","versionType":"python","status":"affected"},{"version":"3.14.0a1","lessThan":"3.14.5rc1","versionType":"python","status":"affected"},{"version":"3.15.0a1","lessThan":"3.15.0b1","versionType":"python","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-21T19:15:36.206348Z","id":"CVE-2026-3298","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@python.org","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://github.com/python/cpython/commit/1274766d3c29007ab77245a72abbf8dce2a9db4d","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/27522b7d6e6588f03e61099dd858cd5a9314e2f2","source":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/95633d2aad4721e25e4dfd9f43dfb6e1edcbd741","source":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/148808","source":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/148809","source":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/KWTPIQBOOOUNQP7UFSLBI437NJDFLA3F/","source":"cna@python.org"}]}},{"cve":{"id":"CVE-2026-46968","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:17:02.760","lastModified":"2026-07-31T15:27:29.943","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"Oracle Java SE","versions":[{"version":"8u491","status":"affected"},{"version":"8u491-perf","status":"affected"},{"version":"11.0.31","status":"affected"},{"version":"17.0.19","status":"affected"},{"version":"21.0.11","status":"affected"},{"version":"25.0.3","status":"affected"},{"version":"26.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T19:21:55.842668Z","id":"CVE-2026-46968","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:1.8.0:update491:*:*:-:*:*:*","matchCriteriaId":"D0DE5FE4-2686-4C60-B4C6-2AC9E7A538D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:1.8.0:update491:*:*:enterprise_performance_pack:*:*:*","matchCriteriaId":"D60FEE5A-22B8-4F6C-AF4F-C8B317C2D102"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:11.0.31:*:*:*:*:*:*:*","matchCriteriaId":"FB3E4F54-F4A3-40E8-8662-EA181BEE59E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:17.0.19:*:*:*:*:*:*:*","matchCriteriaId":"1F21877D-7A65-4208-B050-C6E2D5857861"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:21.0.11:*:*:*:*:*:*:*","matchCriteriaId":"9A3AFF47-354C-4942-9EB7-45D2193EF63E"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:25.0.3:*:*:*:*:*:*:*","matchCriteriaId":"8F08B2DE-C919-46C7-8F5B-76C1FF0534BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:26.0.1:*:*:*:*:*:*:*","matchCriteriaId":"0FCAAFC2-C392-4D78-8027-0D40135AE0E9"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:1.8.0:update491:*:*:-:*:*:*","matchCriteriaId":"26A3520C-C410-4AC7-93CF-69F5CBD23CA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:1.8.0:update491:*:*:enterprise_performance_pack:*:*:*","matchCriteriaId":"35F51EB5-DF63-47B3-9EFF-E52B0538747E"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:11.0.31:*:*:*:*:*:*:*","matchCriteriaId":"2CBF2718-F1CA-4BB6-8FE5-C106C444DFA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:17.0.19:*:*:*:*:*:*:*","matchCriteriaId":"0AF814DE-A1D5-44E6-B868-733F0BB4EB64"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:21.0.11:*:*:*:*:*:*:*","matchCriteriaId":"6FC66081-3173-4BEB-A10E-DBDEDCD7C8E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:25.0.3:*:*:*:*:*:*:*","matchCriteriaId":"A8496CC4-C134-44F9-826A-492C5714B751"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:26.0.1:*:*:*:*:*:*:*","matchCriteriaId":"D3FCB650-0CC3-41E5-8B44-449F4C851DD5"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:graalvm:21.3.18:*:*:*:enterprise:*:*:*","matchCriteriaId":"EF86D60E-69A7-4037-981F-314D48C69EEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:graalvm_for_jdk:17.0.19:*:*:*:*:*:*:*","matchCriteriaId":"2EB67235-B538-415E-ABDD-53446AF5E7B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:graalvm_for_jdk:21.0.11:*:*:*:*:*:*:*","matchCriteriaId":"FBAA4BB5-D7E9-4F1A-AD13-65915A099495"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-46982","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:17:03.240","lastModified":"2026-07-31T15:07:37.327","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal).   The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"Oracle Retail Integration Bus","versions":[{"version":"14.1.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T19:23:50.256308Z","id":"CVE-2026-46982","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:*","matchCriteriaId":"8CFCE558-9972-46A2-8539-C16044F1BAA9"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-46983","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:17:03.347","lastModified":"2026-07-31T15:18:35.987","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"Oracle Retail Integration Bus","versions":[{"version":"16.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T19:23:51.466339Z","id":"CVE-2026-46983","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:*","matchCriteriaId":"822A3C37-86F2-4E91-BE91-2A859F983941"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-47007","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:17:06.143","lastModified":"2026-07-31T15:18:01.287","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Pricing Design Center executes to compromise Oracle Communications Pricing Design Center.  While the vulnerability is in Oracle Communications Pricing Design Center, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Pricing Design Center accessible data as well as  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"Oracle Communications Pricing Design Center","versions":[{"version":"15.0.0.0.0","versionType":"semver","status":"affected"},{"version":"15.0.1.0.0","versionType":"semver","status":"affected"},{"version":"15.1.0.0.0","versionType":"semver","status":"affected"},{"version":"15.2.0.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.0,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-23T15:05:00.929230Z","id":"CVE-2026-47007","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_pricing_design_center:15.0.0.0.0:*:*:*:*:*:*:*","matchCriteriaId":"E8E688D5-E795-458D-A7FE-D8E350822C63"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_pricing_design_center:15.0.1.0.0:*:*:*:*:*:*:*","matchCriteriaId":"3A2797EE-A7D3-4CBE-802A-3096B6C3E953"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_pricing_design_center:15.1.0.0.0:*:*:*:*:*:*:*","matchCriteriaId":"8A965D7E-B9B7-4AFC-A9CC-D8B38719A619"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_pricing_design_center:15.2.0.0.0:*:*:*:*:*:*:*","matchCriteriaId":"683606CC-D89F-424B-A3BE-3DFFFA8A389B"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-47009","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:17:06.373","lastModified":"2026-07-31T15:10:57.357","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"Oracle Agile PLM","versions":[{"version":"9.3.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-28T00:00:00+00:00","id":"CVE-2026-47009","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*","matchCriteriaId":"4305ED0E-30CC-4AEA-8988-3D1EC93A0BB2"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-47010","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:17:06.497","lastModified":"2026-07-31T15:13:21.283","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"Oracle Java SE","versions":[{"version":"8u491","status":"affected"},{"version":"8u491-perf","status":"affected"},{"version":"11.0.31","status":"affected"},{"version":"17.0.19","status":"affected"},{"version":"21.0.11","status":"affected"},{"version":"25.0.3","status":"affected"},{"version":"26.0.1","status":"affected"}]},{"vendor":"Oracle Corporation","product":"Oracle GraalVM for JDK","versions":[{"version":"17.0.19","status":"affected"},{"version":"21.0.11","status":"affected"}]},{"vendor":"Oracle Corporation","product":"Oracle GraalVM Enterprise Edition","versions":[{"version":"21.3.18","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-23T14:58:30.796473Z","id":"CVE-2026-47010","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:graalvm:21.3.18:*:*:*:enterprise:*:*:*","matchCriteriaId":"EF86D60E-69A7-4037-981F-314D48C69EEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:graalvm_for_jdk:17.0.19:*:*:*:*:*:*:*","matchCriteriaId":"2EB67235-B538-415E-ABDD-53446AF5E7B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:graalvm_for_jdk:21.0.11:*:*:*:*:*:*:*","matchCriteriaId":"FBAA4BB5-D7E9-4F1A-AD13-65915A099495"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:1.8.0:update491:*:*:-:*:*:*","matchCriteriaId":"D0DE5FE4-2686-4C60-B4C6-2AC9E7A538D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:1.8.0:update491:*:*:enterprise_performance_pack:*:*:*","matchCriteriaId":"D60FEE5A-22B8-4F6C-AF4F-C8B317C2D102"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:11.0.31:*:*:*:*:*:*:*","matchCriteriaId":"FB3E4F54-F4A3-40E8-8662-EA181BEE59E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:17.0.19:*:*:*:*:*:*:*","matchCriteriaId":"1F21877D-7A65-4208-B050-C6E2D5857861"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:21.0.11:*:*:*:*:*:*:*","matchCriteriaId":"9A3AFF47-354C-4942-9EB7-45D2193EF63E"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:25.0.3:*:*:*:*:*:*:*","matchCriteriaId":"8F08B2DE-C919-46C7-8F5B-76C1FF0534BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:26.0.1:*:*:*:*:*:*:*","matchCriteriaId":"0FCAAFC2-C392-4D78-8027-0D40135AE0E9"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:1.8.0:update491:*:*:-:*:*:*","matchCriteriaId":"26A3520C-C410-4AC7-93CF-69F5CBD23CA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:1.8.0:update491:*:*:enterprise_performance_pack:*:*:*","matchCriteriaId":"35F51EB5-DF63-47B3-9EFF-E52B0538747E"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:11.0.31:*:*:*:*:*:*:*","matchCriteriaId":"2CBF2718-F1CA-4BB6-8FE5-C106C444DFA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:17.0.19:*:*:*:*:*:*:*","matchCriteriaId":"0AF814DE-A1D5-44E6-B868-733F0BB4EB64"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:21.0.11:*:*:*:*:*:*:*","matchCriteriaId":"6FC66081-3173-4BEB-A10E-DBDEDCD7C8E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:25.0.3:*:*:*:*:*:*:*","matchCriteriaId":"A8496CC4-C134-44F9-826A-492C5714B751"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:26.0.1:*:*:*:*:*:*:*","matchCriteriaId":"D3FCB650-0CC3-41E5-8B44-449F4C851DD5"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-47013","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:17:06.857","lastModified":"2026-07-31T14:52:14.140","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in Oracle Java SE (component: JavaFX).   The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"Oracle Java SE","versions":[{"version":"8u491","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-23T15:08:32.445689Z","id":"CVE-2026-47013","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:1.8.0:update491:*:*:-:*:*:*","matchCriteriaId":"26A3520C-C410-4AC7-93CF-69F5CBD23CA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:1.8.0:update491:*:*:-:*:*:*","matchCriteriaId":"D0DE5FE4-2686-4C60-B4C6-2AC9E7A538D5"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-47014","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:17:06.977","lastModified":"2026-07-31T14:44:31.347","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Security).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"Oracle Product Workbench","versions":[{"version":"12.2.3","lessThanOrEqual":"12.2.15","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-23T15:09:16.371266Z","id":"CVE-2026-47014","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:product_workbench:*:*:*:*:*:*:*:*","versionStartIncluding":"12.2.3","versionEndIncluding":"12.2.15","matchCriteriaId":"FF93DBD6-A729-4F7E-A250-9F46266DD041"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-47019","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:17:07.567","lastModified":"2026-07-31T14:13:46.487","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"Oracle Product Hub","versions":[{"version":"12.2.3","lessThanOrEqual":"12.2.15","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-23T15:20:25.600567Z","id":"CVE-2026-47019","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*","versionStartIncluding":"12.2.3","versionEndIncluding":"12.2.15","matchCriteriaId":"790B1A26-C85A-4C28-B04E-ACFFEE4650D1"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61070","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:37.763","lastModified":"2026-07-31T15:23:42.430","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Cash Management).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Argentina","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-24T14:07:23.539029Z","id":"CVE-2026-61070","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61073","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:38.090","lastModified":"2026-07-31T15:23:36.353","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Purchasing).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Brazil","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-24T14:11:25.095999Z","id":"CVE-2026-61073","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61074","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:38.193","lastModified":"2026-07-31T15:23:29.817","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement).   The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Brazil","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-24T14:09:33.529319Z","id":"CVE-2026-61074","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"},{"lang":"en","value":"CWE-287"},{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61232","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:54.023","lastModified":"2026-07-31T15:23:22.770","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Brazil","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T19:21:12.190299Z","id":"CVE-2026-61232","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61233","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:54.133","lastModified":"2026-07-31T15:23:13.700","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Brazil","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T19:20:22.802482Z","id":"CVE-2026-61233","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-284"},{"lang":"en","value":"CWE-287"},{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61234","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:54.243","lastModified":"2026-07-31T15:23:06.733","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement).   The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Brazil accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Brazil","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T19:15:51.468757Z","id":"CVE-2026-61234","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61236","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:54.460","lastModified":"2026-07-31T15:22:59.803","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Staffing).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Brazil","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T19:17:10.548460Z","id":"CVE-2026-61236","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61237","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:54.573","lastModified":"2026-07-31T15:22:54.113","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina.  While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Common Objects Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Argentina","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":5.3}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T18:23:30.339986Z","id":"CVE-2026-61237","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-269"},{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61238","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:54.687","lastModified":"2026-07-31T15:22:48.850","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Argentina","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T18:22:28.320877Z","id":"CVE-2026-61238","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61239","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:54.793","lastModified":"2026-07-31T15:22:39.287","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina.  While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise FIN Common Objects Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Argentina","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":5.3}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T18:21:33.793005Z","id":"CVE-2026-61239","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"},{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61240","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:54.907","lastModified":"2026-07-31T15:22:30.863","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eSettlements).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise FIN Common Objects Argentina executes to compromise PeopleSoft Enterprise FIN Common Objects Argentina.  While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Common Objects Argentina accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Argentina","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T18:20:48.061312Z","id":"CVE-2026-61240","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61242","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:55.010","lastModified":"2026-07-31T15:22:24.467","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina.  While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Argentina","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T18:20:09.887051Z","id":"CVE-2026-61242","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-61243","sourceIdentifier":"secalert_us@oracle.com","published":"2026-07-21T22:18:55.123","lastModified":"2026-07-31T15:22:13.413","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)."}],"affected":[{"source":"secalert_us@oracle.com","affectedData":[{"vendor":"Oracle Corporation","product":"PeopleSoft Enterprise FIN Common Objects Argentina","versions":[{"version":"9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert_us@oracle.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T18:14:39.289787Z","id":"CVE-2026-61243","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-269"},{"lang":"en","value":"CWE-284"},{"lang":"en","value":"CWE-287"},{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*","matchCriteriaId":"12D96C0E-616B-4FE3-95FE-255A5368C282"}]}]}],"references":[{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-16615","sourceIdentifier":"secalert@redhat.com","published":"2026-07-22T17:16:55.863","lastModified":"2026-07-31T14:16:47.483","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated \"code verifier\" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"GNOME","product":"librest","defaultStatus":"affected","collectionURL":"https://gitlab.gnome.org/GNOME/librest","packageName":"librest"},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rest","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:0.9.1-11.el10_2.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-22T16:43:25.862726Z","id":"CVE-2026-16615","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-338"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:47085","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-16615","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2504432","source":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/librest/-/issues/25","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-64600","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-23T06:16:50.493","lastModified":"2026-07-31T14:16:51.023","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: resample the data fork mapping after cycling ILOCK\n\nxfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode,\na data fork mapping, and a cow fork mapping.  Unfortunately, these two\nhelpers cycle the ILOCK to grab a transaction, which means that the\nmappings are stale as soon as we reacquire the ILOCK.  Currently we\nrefresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but\nwe don't refresh the data fork mapping beforehand, which means that the\nxfs_bmap_trim_cow in that function queries the refcount btree about the\nwrong physical blocks and returns an inaccurate value in *shared.\n\nIf *shared is now false, the directio write proceeds with a stale data\nfork mapping.  Fix this by querying the data fork mapping if the\nsequence counter changes across the ILOCK cycle."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/xfs/xfs_reflink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5","lessThan":"dc11be133efca5fe3a2fb02b016dee825cc12f18","versionType":"git","status":"affected"},{"version":"3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5","lessThan":"b8c9aa832b52680ee40d6cab0efb081f9a69df05","versionType":"git","status":"affected"},{"version":"3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5","lessThan":"50f0012da1040f69a4e788cd9aed587c9a04983f","versionType":"git","status":"affected"},{"version":"3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5","lessThan":"e705d81a7193dd19e69b8e2bad4696d78a4ea075","versionType":"git","status":"affected"},{"version":"3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5","lessThan":"206c09b04dc5469c7ff14d8aceff2d47c88078d9","versionType":"git","status":"affected"},{"version":"3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5","lessThan":"44f891bc088958399eec27f7604928694aa35581","versionType":"git","status":"affected"},{"version":"3c68d44a2b49a0ac9165faa9c191e1e618c8a8d5","lessThan":"2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/xfs/xfs_reflink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/206c09b04dc5469c7ff14d8aceff2d47c88078d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/44f891bc088958399eec27f7604928694aa35581","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50f0012da1040f69a4e788cd9aed587c9a04983f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8c9aa832b52680ee40d6cab0efb081f9a69df05","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc11be133efca5fe3a2fb02b016dee825cc12f18","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e705d81a7193dd19e69b8e2bad4696d78a4ea075","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/22/14","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/22/18","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/22/19","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/31/3","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-16768","sourceIdentifier":"secalert@redhat.com","published":"2026-07-23T17:16:28.037","lastModified":"2026-07-31T14:16:47.617","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"GNOME","product":"gdk-pixbuf","defaultStatus":"affected","collectionURL":"https://gitlab.gnome.org/GNOME/gdk-pixbuf","packageName":"gdk-pixbuf"},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gdk-pixbuf2","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gdk-pixbuf2","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gdk-pixbuf2","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gdk-pixbuf2","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gdk-pixbuf2","cpes":["cpe:/o:redhat:enterprise_linux:9"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-23T17:49:43.531984Z","id":"CVE-2026-16768","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-16768","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2506437","source":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302","source":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-16554","sourceIdentifier":"cvd@cert.pl","published":"2026-07-27T09:16:37.383","lastModified":"2026-07-31T14:16:47.337","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop overflows the heap allocation. An attacker supplying a crafted JSON string to an application using cJSON on a 32-bit platform can cause a heap buffer overflow, potentially leading to remote code execution, information disclosure, or denial of service.\n\n\n\n\nBecause project creator contact attempts were unsuccessful, the vulnerability has only been confirmed in version 1.7.19 but may also affect other versions."}],"affected":[{"source":"cvd@cert.pl","affectedData":[{"vendor":"DaveGamble","product":"cJSON","defaultStatus":"unaffected","modules":["cJSON.c"],"repo":"https://github.com/DaveGamble/cJSON","versions":[{"version":"1.7.19","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cvd@cert.pl","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-27T10:24:13.881075Z","id":"CVE-2026-16554","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cvd@cert.pl","type":"Secondary","description":[{"lang":"en","value":"CWE-190"}]}],"references":[{"url":"https://cert.pl/en/posts/2026/07/CVE-2026-16554","source":"cvd@cert.pl"},{"url":"https://github.com/DaveGamble/cJSON","source":"cvd@cert.pl"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/30/26","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/31/4","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-51296","sourceIdentifier":"cve@mitre.org","published":"2026-07-27T16:17:38.347","lastModified":"2026-07-31T15:16:33.347","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51297","sourceIdentifier":"cve@mitre.org","published":"2026-07-27T16:17:38.933","lastModified":"2026-07-31T15:16:55.740","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51298","sourceIdentifier":"cve@mitre.org","published":"2026-07-27T16:17:39.047","lastModified":"2026-07-31T15:17:11.813","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51300","sourceIdentifier":"cve@mitre.org","published":"2026-07-27T16:17:39.153","lastModified":"2026-07-31T15:17:27.450","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51302","sourceIdentifier":"cve@mitre.org","published":"2026-07-27T16:17:39.273","lastModified":"2026-07-31T15:17:27.573","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51303","sourceIdentifier":"cve@mitre.org","published":"2026-07-27T16:17:39.380","lastModified":"2026-07-31T15:17:42.670","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51304","sourceIdentifier":"cve@mitre.org","published":"2026-07-27T16:17:39.500","lastModified":"2026-07-31T15:17:42.770","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51235","sourceIdentifier":"cve@mitre.org","published":"2026-07-27T18:16:56.117","lastModified":"2026-07-31T15:16:28.533","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51244","sourceIdentifier":"cve@mitre.org","published":"2026-07-27T19:17:16.447","lastModified":"2026-07-31T15:16:29.283","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-66759","sourceIdentifier":"secalert@redhat.com","published":"2026-07-27T19:17:23.747","lastModified":"2026-07-31T15:18:00.883","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"GNOME","product":"GIMP","defaultStatus":"unaffected","collectionURL":"https://gitlab.gnome.org/GNOME/gimp","packageName":"gimp","versions":[{"version":"2.99.14","lessThan":"*","versionType":"semver","status":"affected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gimp","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gimp","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gimp:2.8/gimp","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gimp","cpes":["cpe:/o:redhat:enterprise_linux:9"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-27T19:25:27.419672Z","id":"CVE-2026-66759","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-66759","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507557","source":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/gimp/-/issues/16528","source":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/gimp/-/issues/16528","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-51251","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T15:17:16.227","lastModified":"2026-07-31T15:16:29.760","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51252","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T15:17:16.370","lastModified":"2026-07-31T15:16:29.837","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51254","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T15:17:16.507","lastModified":"2026-07-31T15:16:29.980","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51259","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T15:17:16.640","lastModified":"2026-07-31T15:16:30.333","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51260","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T15:17:16.780","lastModified":"2026-07-31T15:16:30.467","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51261","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T15:17:16.943","lastModified":"2026-07-31T15:16:30.560","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51263","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T16:18:50.137","lastModified":"2026-07-31T15:16:30.710","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51266","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T16:18:50.270","lastModified":"2026-07-31T15:16:30.930","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51267","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T16:18:50.400","lastModified":"2026-07-31T15:16:31.003","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51268","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T16:18:50.533","lastModified":"2026-07-31T15:16:31.130","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51269","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T16:18:50.670","lastModified":"2026-07-31T15:16:31.330","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51270","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T16:18:50.803","lastModified":"2026-07-31T15:16:31.407","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51271","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T16:18:50.940","lastModified":"2026-07-31T15:16:31.477","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51273","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T17:16:46.540","lastModified":"2026-07-31T15:16:31.840","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51274","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T17:16:46.673","lastModified":"2026-07-31T15:16:31.933","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51275","sourceIdentifier":"cve@mitre.org","published":"2026-07-28T17:16:46.807","lastModified":"2026-07-31T15:16:32.003","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-17689","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:31.220","lastModified":"2026-07-31T15:27:35.290","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:31:42.670179Z","id":"CVE-2026-17689","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-457"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/517045160","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17693","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:31.663","lastModified":"2026-07-31T15:27:51.113","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:21:49.647980Z","id":"CVE-2026-17693","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/517448723","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17696","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:31.973","lastModified":"2026-07-31T15:28:02.007","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:31:44.649303Z","id":"CVE-2026-17696","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1300"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/517550034","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17700","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:32.413","lastModified":"2026-07-31T15:28:16.303","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:31:46.957249Z","id":"CVE-2026-17700","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/517789833","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17730","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:35.707","lastModified":"2026-07-31T15:28:27.350","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:31:50.975522Z","id":"CVE-2026-17730","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1300"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/40057032","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17740","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:36.820","lastModified":"2026-07-31T15:28:39.653","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:42:48.365973Z","id":"CVE-2026-17740","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-457"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/498827800","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17742","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:37.050","lastModified":"2026-07-31T15:28:51.350","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient policy enforcement in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:42:47.655930Z","id":"CVE-2026-17742","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/499003233","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17753","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:38.240","lastModified":"2026-07-31T15:29:00.807","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:42:46.670850Z","id":"CVE-2026-17753","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/501628355","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17757","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:38.650","lastModified":"2026-07-31T15:29:47.197","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:42:45.494555Z","id":"CVE-2026-17757","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-457"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/502351526","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17760","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:39.027","lastModified":"2026-07-31T15:29:11.667","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Side-channel information leakage in NoStatePrefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:42:44.652462Z","id":"CVE-2026-17760","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1300"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/506473189","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17763","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:39.367","lastModified":"2026-07-31T15:29:24.483","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Inappropriate implementation in GPU in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:42:42.667989Z","id":"CVE-2026-17763","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/511738693","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17765","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:39.660","lastModified":"2026-07-31T15:29:36.767","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Inappropriate implementation in WebProtect in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T13:42:41.570385Z","id":"CVE-2026-17765","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"151.0.7922.72","matchCriteriaId":"5306E563-AFD7-43CB-AFC8-CE1F449BA94C"}]}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/511765328","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-17797","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:43.107","lastModified":"2026-07-31T15:16:27.587","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:07:58.329160Z","id":"CVE-2026-17797","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/514441966","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-17799","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:43.307","lastModified":"2026-07-31T15:16:27.793","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a malicious file. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:07:42.170067Z","id":"CVE-2026-17799","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/514461031","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-17804","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:43.847","lastModified":"2026-07-31T14:16:47.760","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:59:40.143985Z","id":"CVE-2026-17804","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/515448947","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-17805","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:43.950","lastModified":"2026-07-31T14:16:47.940","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient policy enforcement in Glic in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:57:48.418523Z","id":"CVE-2026-17805","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-602"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/516420806","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-17806","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:44.053","lastModified":"2026-07-31T14:16:48.143","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":3.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:05:26.814206Z","id":"CVE-2026-17806","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/516433058","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-17809","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:44.380","lastModified":"2026-07-31T14:16:48.323","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":3.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:04:56.906937Z","id":"CVE-2026-17809","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/516813317","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-17811","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:44.603","lastModified":"2026-07-31T14:16:48.520","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:04:29.662999Z","id":"CVE-2026-17811","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/516954622","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-17812","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:44.730","lastModified":"2026-07-31T14:16:48.703","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Inappropriate implementation in DigitalCredentials in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:04:08.309065Z","id":"CVE-2026-17812","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-451"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/517101596","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-17813","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:44.833","lastModified":"2026-07-31T14:16:48.887","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:55:00.474633Z","id":"CVE-2026-17813","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-602"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/517184957","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-17814","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:44.937","lastModified":"2026-07-31T14:16:49.090","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:56:22.954666Z","id":"CVE-2026-17814","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/517312048","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-17818","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:45.363","lastModified":"2026-07-31T14:16:49.280","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:43:13.754384Z","id":"CVE-2026-17818","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/517466133","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-17908","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-30T01:16:54.890","lastModified":"2026-07-31T14:16:49.480","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"151.0.7922.72","lessThan":"151.0.7922.72","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":3.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:02:09.911231Z","id":"CVE-2026-17908","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/499062890","source":"chrome-cve-admin@google.com"}]}},{"cve":{"id":"CVE-2026-5219","sourceIdentifier":"iletisim@usom.gov.tr","published":"2026-07-30T14:17:01.747","lastModified":"2026-07-31T14:16:50.457","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery.\n\nThis issue affects E-Commerce Pack: before 5.03.01.49."}],"affected":[{"source":"iletisim@usom.gov.tr","affectedData":[{"vendor":"Softtr Information Technology Trade Ltd. Co.","product":"E-Commerce Pack","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.03.01.49","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T15:14:37.884479Z","id":"CVE-2026-5219","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"iletisim@usom.gov.tr","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0702","source":"iletisim@usom.gov.tr"}]}},{"cve":{"id":"CVE-2026-51290","sourceIdentifier":"cve@mitre.org","published":"2026-07-30T17:16:32.133","lastModified":"2026-07-31T15:16:32.987","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51291","sourceIdentifier":"cve@mitre.org","published":"2026-07-30T17:16:32.240","lastModified":"2026-07-31T15:16:33.057","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51292","sourceIdentifier":"cve@mitre.org","published":"2026-07-30T17:16:32.347","lastModified":"2026-07-31T15:16:33.113","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51293","sourceIdentifier":"cve@mitre.org","published":"2026-07-30T17:16:32.453","lastModified":"2026-07-31T15:16:33.173","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51294","sourceIdentifier":"cve@mitre.org","published":"2026-07-30T17:16:32.560","lastModified":"2026-07-31T15:16:33.230","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51295","sourceIdentifier":"cve@mitre.org","published":"2026-07-30T17:16:32.663","lastModified":"2026-07-31T15:16:33.293","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51272","sourceIdentifier":"cve@mitre.org","published":"2026-07-30T19:18:05.820","lastModified":"2026-07-31T15:16:31.607","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-67529","sourceIdentifier":"security-advisories@github.com","published":"2026-07-30T20:18:14.750","lastModified":"2026-07-31T15:18:01.293","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /api/v3/cost_entries rendered _links.workPackage.title and _links.workPackage.href through associated_resource in modules/costs/lib/api/v3/time_entries/time_entry_representer.rb and modules/costs/lib/api/v3/cost_entries/cost_entry_representer.rb without checking WorkPackage.visible or view_work_packages, allowing users with view_time_entries or view_cost_entries to read private work package subjects and ids. This issue is fixed in 17.6.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"opf","product":"openproject","versions":[{"version":"< 17.6.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:37:45.456126Z","id":"CVE-2026-67529","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/opf/openproject/commit/9e9e562e516a647f35267df715d875f58b267c18","source":"security-advisories@github.com"},{"url":"https://github.com/opf/openproject/commit/c31c2f958c8e72a0d0d748d728221d57f3ef9001","source":"security-advisories@github.com"},{"url":"https://github.com/opf/openproject/pull/23888","source":"security-advisories@github.com"},{"url":"https://github.com/opf/openproject/pull/23936","source":"security-advisories@github.com"},{"url":"https://github.com/opf/openproject/releases/tag/v17.6.0","source":"security-advisories@github.com"},{"url":"https://github.com/opf/openproject/security/advisories/GHSA-v3j7-vqwv-5w5q","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2025-69938","sourceIdentifier":"cve@mitre.org","published":"2026-07-30T21:16:52.670","lastModified":"2026-07-31T15:16:27.233","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:31:45.647795Z","id":"CVE-2025-69938","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/codeastro/20250811-membership-management-system-renew.php-membershiptype-sqli/20250811-membership-management-system-renew.php-membershiptype-sqli.md","source":"cve@mitre.org"},{"url":"https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/codeastro/20250811-membership-management-system-renew.php-membershiptype-sqli/20250811-membership-management-system-renew.php-membershiptype-sqli.md","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-68500","sourceIdentifier":"security-advisories@github.com","published":"2026-07-30T21:18:13.007","lastModified":"2026-07-31T15:18:01.430","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced Sylius order, allowing an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring funds for that order. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"Sylius","product":"MolliePlugin","versions":[{"version":"< 2.2.8","status":"affected"},{"version":">= 3.0.0, < 3.2.4","status":"affected"},{"version":">= 3.3.0, < 3.3.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:36:41.859832Z","id":"CVE-2026-68500","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/Sylius/MolliePlugin/commit/01316b3ad3cf82e3c5ad160115d0a2cf89174e49","source":"security-advisories@github.com"},{"url":"https://github.com/Sylius/MolliePlugin/commit/153c754486b1bc597b67a90ac07ef71cd7958267","source":"security-advisories@github.com"},{"url":"https://github.com/Sylius/MolliePlugin/commit/d1f7753e92106e8bf3bedcfc61b02ea7b8e1c38a","source":"security-advisories@github.com"},{"url":"https://github.com/Sylius/MolliePlugin/pull/351","source":"security-advisories@github.com"},{"url":"https://github.com/Sylius/MolliePlugin/pull/352","source":"security-advisories@github.com"},{"url":"https://github.com/Sylius/MolliePlugin/pull/354","source":"security-advisories@github.com"},{"url":"https://github.com/Sylius/MolliePlugin/releases/tag/v2.2.8","source":"security-advisories@github.com"},{"url":"https://github.com/Sylius/MolliePlugin/releases/tag/v3.2.4","source":"security-advisories@github.com"},{"url":"https://github.com/Sylius/MolliePlugin/releases/tag/v3.3.1","source":"security-advisories@github.com"},{"url":"https://github.com/Sylius/MolliePlugin/security/advisories/GHSA-rc52-c4hv-w89p","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-68502","sourceIdentifier":"security-advisories@github.com","published":"2026-07-30T21:18:13.317","lastModified":"2026-07-31T15:18:01.563","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reaching LazyOwnShell.do_cmd and subprocess.call(command, shell=True), allowing unauthenticated remote code execution in the C2 process. This issue is fixed in 0.2.154."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"grisuno","product":"LazyOwn","versions":[{"version":"< 0.2.154","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:07:18.664082Z","id":"CVE-2026-68502","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/grisuno/LazyOwn/commit/2e1e3a7b5da8149ae28a970b5883aefa42921652","source":"security-advisories@github.com"},{"url":"https://github.com/grisuno/LazyOwn/releases/tag/release/0.2.154","source":"security-advisories@github.com"},{"url":"https://github.com/grisuno/LazyOwn/security/advisories/GHSA-fr84-8cfg-59w4","source":"security-advisories@github.com"},{"url":"https://github.com/grisuno/LazyOwn/security/advisories/GHSA-fr84-8cfg-59w4","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-55496","sourceIdentifier":"security-advisories@github.com","published":"2026-07-31T04:17:22.877","lastModified":"2026-07-31T14:16:50.340","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to enumerate email addresses and profile metadata for inactive or banned accounts. The service calls userClient.SearchActive, but despite its name that method filters only by email/nickname keyword and never adds a StatusActive predicate — while the sibling lookups GetActiveByID and GetActiveByDavAccount, defined a few lines above it, do. Search hits are serialized at RedactLevelUser, which includes the email address. This issue is fixed in version 4.17.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"cloudreve","product":"cloudreve","versions":[{"version":"4.17.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:00:41.421611Z","id":"CVE-2026-55496","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-359"}]}],"references":[{"url":"https://github.com/cloudreve/cloudreve/commit/7e1289d552794bdbeb551be78456115c87dcb3da","source":"security-advisories@github.com"},{"url":"https://github.com/cloudreve/cloudreve/releases/tag/4.17.0","source":"security-advisories@github.com"},{"url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-8r7f-r8hj-r3rv","source":"security-advisories@github.com"},{"url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-8r7f-r8hj-r3rv","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-63220","sourceIdentifier":"security-advisories@github.com","published":"2026-07-31T04:17:24.337","lastModified":"2026-07-31T14:16:50.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as secure. This may have impacted applications that rely on isSecure(), force_https(), forceGlobalSecureRequests, or similar logic to enforce HTTPS-only access or make security-sensitive decisions. Exploitability depends on deployment configuration. Applications are most exposed if the backend is reachable directly over HTTP, or if a reverse proxy/load balancer forwards client-supplied forwarding headers without stripping or overwriting them. This issue has been fixed in version 4.7.4."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"codeigniter4","product":"CodeIgniter4","versions":[{"version":"< 4.7.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:58:12.832050Z","id":"CVE-2026-63220","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-348"}]}],"references":[{"url":"https://github.com/codeigniter4/CodeIgniter4/commit/ecbf044666bed41d23f07518096d9843fe6c08b0","source":"security-advisories@github.com"},{"url":"https://github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4","source":"security-advisories@github.com"},{"url":"https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-7wmf-pw8j-mc78","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-63221","sourceIdentifier":"security-advisories@github.com","published":"2026-07-31T06:16:31.603","lastModified":"2026-07-31T14:16:50.873","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path. Regular delete() operations escape where() binds correctly. This issue is fixed in version 4.7.4."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"codeigniter4","product":"CodeIgniter4","versions":[{"version":">= 4.3.0, < 4.7.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:48:17.706062Z","id":"CVE-2026-63221","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://github.com/codeigniter4/CodeIgniter4/commit/f5e463b9a3e986389ce285963e51a7f1fab6559f","source":"security-advisories@github.com"},{"url":"https://github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4","source":"security-advisories@github.com"},{"url":"https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-c9w5-rwh3-7pm9","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-14317","sourceIdentifier":"contact@wpscan.com","published":"2026-07-31T07:16:24.490","lastModified":"2026-07-31T14:16:45.777","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The GiveWP  WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"GiveWP","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.16.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:35:11.057987Z","id":"CVE-2026-14317","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://wpscan.com/vulnerability/fa6f5470-b30d-4052-aacd-a0571d4678ac/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14333","sourceIdentifier":"contact@wpscan.com","published":"2026-07-31T07:16:24.703","lastModified":"2026-07-31T14:16:45.960","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Demi  WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Demi","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"0.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:33:56.020249Z","id":"CVE-2026-14333","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://wpscan.com/vulnerability/df673b6f-2957-460a-b6fe-6e656d9193e0/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14830","sourceIdentifier":"contact@wpscan.com","published":"2026-07-31T07:16:25.097","lastModified":"2026-07-31T14:16:46.133","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"FlxWoo","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:29:33.050188Z","id":"CVE-2026-14830","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://wpscan.com/vulnerability/b866258c-b49b-40db-a0ff-6c0921b5c89f/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14833","sourceIdentifier":"contact@wpscan.com","published":"2026-07-31T07:16:25.207","lastModified":"2026-07-31T14:16:46.297","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption in the browser, allowing users with author-level access and above (who lack the unfiltered_html capability) to store JavaScript that runs when a visitor or administrator opens the lightbox."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Lightbox with PhotoSwipe","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.9.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:28:59.332598Z","id":"CVE-2026-14833","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://wpscan.com/vulnerability/aae59cb8-b259-464e-a86b-164d89f61342/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14843","sourceIdentifier":"contact@wpscan.com","published":"2026-07-31T07:16:25.420","lastModified":"2026-07-31T14:16:46.470","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the personal data of any person record."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Events Made Easy","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.1.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:27:12.877233Z","id":"CVE-2026-14843","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://wpscan.com/vulnerability/0b445129-19e2-4240-a79a-d3190161d369/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14847","sourceIdentifier":"contact@wpscan.com","published":"2026-07-31T07:16:25.640","lastModified":"2026-07-31T14:16:46.643","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Paid Membership Subscriptions  WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Paid Membership Subscriptions","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:26:21.998228Z","id":"CVE-2026-14847","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://wpscan.com/vulnerability/5cd6d414-8d7d-4627-9649-af092a1afb75/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14849","sourceIdentifier":"contact@wpscan.com","published":"2026-07-31T07:16:25.750","lastModified":"2026-07-31T14:16:46.820","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Paid Membership Subscriptions  WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Paid Membership Subscriptions","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:25:51.301047Z","id":"CVE-2026-14849","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-552"}]}],"references":[{"url":"https://wpscan.com/vulnerability/306a498d-0740-479b-b182-71fc3d7452bb/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14927","sourceIdentifier":"contact@wpscan.com","published":"2026-07-31T07:16:26.280","lastModified":"2026-07-31T14:16:46.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The FluentCart A New Era of eCommerce  WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"FluentCart A New Era of eCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.5.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:23:12.382498Z","id":"CVE-2026-14927","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://wpscan.com/vulnerability/8e0d0e5d-b515-482f-aede-f7ed2046e4e3/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14929","sourceIdentifier":"contact@wpscan.com","published":"2026-07-31T07:16:26.500","lastModified":"2026-07-31T14:16:47.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The JS Help Desk  WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"JS Help Desk","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.1.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T13:24:19.830539Z","id":"CVE-2026-14929","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://wpscan.com/vulnerability/2d786e43-6dbc-4d63-844e-2ca1384cdfd3/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-28144","sourceIdentifier":"audit@patchstack.com","published":"2026-07-31T14:16:49.800","lastModified":"2026-07-31T14:16:49.800","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data.\n\nThis issue affects WP Maps: from n/a through 4.9.6."}],"affected":[{"source":"audit@patchstack.com","affectedData":[{"vendor":"Flipper Code","product":"WP Maps","defaultStatus":"unaffected","collectionURL":"https://wordpress.org/plugins","packageName":"wp-google-map-plugin","versions":[{"version":"n/a","lessThanOrEqual":"4.9.6","versionType":"custom","status":"affected","changes":[{"at":"4.9.7","status":"unaffected"}]}]}]}],"metrics":{"cvssMetricV31":[{"source":"audit@patchstack.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:00:34.783371Z","id":"CVE-2026-28144","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"audit@patchstack.com","type":"Primary","description":[{"lang":"en","value":"CWE-201"}]}],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/wp-google-map-plugin/vulnerability/wordpress-wp-maps-plugin-4-9-6-sensitive-data-exposure-vulnerability?_s_id=cve","source":"audit@patchstack.com"}]}},{"cve":{"id":"CVE-2026-28145","sourceIdentifier":"audit@patchstack.com","published":"2026-07-31T14:16:49.967","lastModified":"2026-07-31T14:16:49.967","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State.\n\nThis issue affects MasterStudy LMS: from n/a through 3.7.39."}],"affected":[{"source":"audit@patchstack.com","affectedData":[{"vendor":"StylemixThemes","product":"MasterStudy LMS","defaultStatus":"unaffected","collectionURL":"https://wordpress.org/plugins","packageName":"masterstudy-lms-learning-management-system","versions":[{"version":"n/a","lessThanOrEqual":"3.7.39","versionType":"custom","status":"affected","changes":[{"at":"3.7.40","status":"unaffected"}]}]}]}],"metrics":{"cvssMetricV31":[{"source":"audit@patchstack.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:00:59.889282Z","id":"CVE-2026-28145","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"audit@patchstack.com","type":"Primary","description":[{"lang":"en","value":"CWE-345"}]}],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/masterstudy-lms-learning-management-system/vulnerability/wordpress-masterstudy-lms-plugin-3-7-39-broken-access-control-vulnerability?_s_id=cve","source":"audit@patchstack.com"}]}},{"cve":{"id":"CVE-2026-65636","sourceIdentifier":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","published":"2026-07-31T14:16:51.240","lastModified":"2026-07-31T15:18:00.693","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inject arbitrary content into generated YAML documents through document comments. Ymlr.document!/2 interpolates each caller-supplied comment string into the output behind a single # prefix without validating it or escaping line breaks. Because a YAML comment is terminated by a line break, the first carriage return or line feed in the comment string ends the comment context and everything after it is emitted at column 0 of the document body.\n\nAn attacker who controls text that the host application passes as a comment can forge top-level mapping keys, override values the application itself set, and emit --- or ... markers that split the output into additional documents. Downstream consumers of the generated YAML, such as configuration loaders, deployment manifests, CI pipelines and data importers, parse the injected content as legitimate data. The same clause backs Ymlr.document/2, Ymlr.documents!/2 and Ymlr.documents/2, so every document encoding entry point is affected.\n\nThis vulnerability is associated with program files lib/ymlr.ex and program routines 'Elixir.Ymlr':document!/2, 'Elixir.Ymlr':documents!/2.\n\nThis issue affects ymlr from 0.0.1 before 5.1.6."}],"affected":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","affectedData":[{"vendor":"ufirstgroup","product":"ymlr","defaultStatus":"unaffected","collectionURL":"https://repo.hex.pm","packageName":"ymlr","cpes":["cpe:2.3:a:ufirstgroup:ymlr:*:*:*:*:*:*:*:*"],"modules":["Elixir.Ymlr"],"programFiles":["lib/ymlr.ex"],"programRoutines":[{"name":"'Elixir.Ymlr':document!/2"},{"name":"'Elixir.Ymlr':documents!/2"}],"repo":"https://github.com/ufirstgroup/ymlr","packageURL":"pkg:hex/ymlr","versions":[{"version":"0.0.1","lessThan":"5.1.6","versionType":"semver","status":"affected"}]},{"vendor":"ufirstgroup","product":"ymlr","defaultStatus":"unaffected","collectionURL":"https://github.com","packageName":"ufirstgroup/ymlr","cpes":["cpe:2.3:a:ufirstgroup:ymlr:*:*:*:*:*:*:*:*"],"modules":["Elixir.Ymlr"],"programFiles":["lib/ymlr.ex"],"programRoutines":[{"name":"'Elixir.Ymlr':document!/2"},{"name":"'Elixir.Ymlr':documents!/2"}],"repo":"https://github.com/ufirstgroup/ymlr","packageURL":"pkg:github/ufirstgroup/ymlr","versions":[{"version":"0c11a86de83825e91c27cecaccb03f36416d8fe0","lessThan":"42a0bf8b2af44b0e7c42d0b7044c8588ca5866dc","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T14:28:31.525792Z","id":"CVE-2026-65636","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","description":[{"lang":"en","value":"CWE-93"}]}],"references":[{"url":"https://cna.erlef.org/cves/CVE-2026-65636.html","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ufirstgroup/ymlr/commit/42a0bf8b2af44b0e7c42d0b7044c8588ca5866dc","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ufirstgroup/ymlr/commit/7e53061fb2809b787fba0373c46b78e253c83adc","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ufirstgroup/ymlr/security/advisories/GHSA-p8qx-7cp9-v6c9","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-65636","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"}]}},{"cve":{"id":"CVE-2026-51229","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:28.130","lastModified":"2026-07-31T15:16:28.130","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51230","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:28.213","lastModified":"2026-07-31T15:16:28.213","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51231","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:28.280","lastModified":"2026-07-31T15:16:28.280","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51232","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:28.340","lastModified":"2026-07-31T15:16:28.340","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51233","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:28.410","lastModified":"2026-07-31T15:16:28.410","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51234","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:28.473","lastModified":"2026-07-31T15:16:28.473","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51236","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:28.753","lastModified":"2026-07-31T15:16:28.753","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51237","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:28.823","lastModified":"2026-07-31T15:16:28.823","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51238","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:28.887","lastModified":"2026-07-31T15:16:28.887","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51239","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:28.950","lastModified":"2026-07-31T15:16:28.950","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51240","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:29.020","lastModified":"2026-07-31T15:16:29.020","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51241","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:29.083","lastModified":"2026-07-31T15:16:29.083","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51242","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:29.153","lastModified":"2026-07-31T15:16:29.153","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51243","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:29.220","lastModified":"2026-07-31T15:16:29.220","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51245","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:29.353","lastModified":"2026-07-31T15:16:29.353","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51246","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:29.417","lastModified":"2026-07-31T15:16:29.417","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51247","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:29.487","lastModified":"2026-07-31T15:16:29.487","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51248","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:29.573","lastModified":"2026-07-31T15:16:29.573","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51249","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:29.640","lastModified":"2026-07-31T15:16:29.640","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51250","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:29.700","lastModified":"2026-07-31T15:16:29.700","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51253","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:29.897","lastModified":"2026-07-31T15:16:29.897","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51255","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:30.057","lastModified":"2026-07-31T15:16:30.057","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51256","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:30.127","lastModified":"2026-07-31T15:16:30.127","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51257","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:30.190","lastModified":"2026-07-31T15:16:30.190","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51258","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:30.260","lastModified":"2026-07-31T15:16:30.260","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51262","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:30.640","lastModified":"2026-07-31T15:16:30.640","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51264","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:30.787","lastModified":"2026-07-31T15:16:30.787","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51265","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:30.857","lastModified":"2026-07-31T15:16:30.857","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51276","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.080","lastModified":"2026-07-31T15:16:32.080","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51277","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.150","lastModified":"2026-07-31T15:16:32.150","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51278","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.223","lastModified":"2026-07-31T15:16:32.223","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51279","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.283","lastModified":"2026-07-31T15:16:32.283","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51280","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.350","lastModified":"2026-07-31T15:16:32.350","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51281","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.410","lastModified":"2026-07-31T15:16:32.410","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51282","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.477","lastModified":"2026-07-31T15:16:32.477","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51283","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.543","lastModified":"2026-07-31T15:16:32.543","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51284","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.600","lastModified":"2026-07-31T15:16:32.600","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51285","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.667","lastModified":"2026-07-31T15:16:32.667","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51286","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.730","lastModified":"2026-07-31T15:16:32.730","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51287","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.800","lastModified":"2026-07-31T15:16:32.800","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51288","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.860","lastModified":"2026-07-31T15:16:32.860","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51289","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:16:32.923","lastModified":"2026-07-31T15:16:32.923","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51299","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:17:27.387","lastModified":"2026-07-31T15:17:27.387","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-51301","sourceIdentifier":"cve@mitre.org","published":"2026-07-31T15:17:27.520","lastModified":"2026-07-31T15:17:27.520","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-67350","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-07-31T15:18:01.103","lastModified":"2026-07-31T15:18:01.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can craft trusted-looking URLs leveraging the legitimate blog domain to conduct phishing, deliver malware, or bypass URL reputation filters."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"s9y","product":"Serendipity","defaultStatus":"unaffected","repo":"https://github.com/s9y/Serendipity","packageURL":"pkg:github/s9y/Serendipity","versions":[{"version":"0","lessThan":"2.6.1","versionType":"semver","status":"affected"},{"version":"2.6.1","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"references":[{"url":"https://github.com/s9y/Serendipity/security/advisories/GHSA-77rw-27c5-4hxm","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/serendipity-open-redirect-via-exit-php","source":"disclosure@vulncheck.com"}]}}]}