From c6c9c89eb628574af37682c462ea9e85f1b89b89 Mon Sep 17 00:00:00 2001 From: Patrick Linnane Date: Thu, 13 Aug 2026 11:55:08 -0700 Subject: [PATCH] Add comparable CPANSA candidates from the backfill Adds the 128 comparable CPANSA records (87 fixed, 41 affected) held out of the shard backfill for batch review, and removes their temporary denylist hold in the same change, as the denylist header requires. Signed-off-by: Patrick Linnane --- ...BREW-abcde-CPANSA-Mojolicious-2014-01.json | 61 ++++ ...BREW-abcde-CPANSA-Mojolicious-2015-01.json | 65 +++++ ...BREW-abcde-CPANSA-Mojolicious-2018-02.json | 65 +++++ ...BREW-abcde-CPANSA-Mojolicious-2018-03.json | 65 +++++ ...BREW-abcde-CPANSA-Mojolicious-2018-04.json | 61 ++++ ...BREW-abcde-CPANSA-Mojolicious-2021-02.json | 58 ++++ ...BREW-abcde-CPANSA-Mojolicious-2022-03.json | 66 +++++ advisories/BREW-abcde-CVE-2009-5074.json | 61 ++++ advisories/BREW-abcde-CVE-2010-4802.json | 76 +++++ advisories/BREW-abcde-CVE-2010-4803.json | 68 +++++ advisories/BREW-abcde-CVE-2011-1589.json | 148 ++++++++++ advisories/BREW-abcde-CVE-2011-1841.json | 76 +++++ advisories/BREW-abcde-CVE-2018-25100.json | 78 ++++++ advisories/BREW-abcde-CVE-2020-36829.json | 71 +++++ advisories/BREW-abcde-CVE-2021-47208.json | 67 +++++ advisories/BREW-abcde-CVE-2024-58134.json | 119 ++++++++ advisories/BREW-abcde-CVE-2024-58135.json | 127 +++++++++ advisories/BREW-abcde-CVE-2026-14803.json | 88 ++++++ advisories/BREW-abcde-CVE-2026-15747.json | 88 ++++++ ...BREW-amtterm-CPANSA-SOAP-Lite-2000-01.json | 61 ++++ advisories/BREW-amtterm-CVE-2002-1742.json | 61 ++++ advisories/BREW-amtterm-CVE-2015-8978.json | 70 +++++ .../BREW-biber-CPANSA-Mozilla-CA-2011-34.json | 69 +++++ advisories/BREW-biber-CVE-2024-39689.json | 89 ++++++ advisories/BREW-biber-CVE-2026-12844.json | 88 ++++++ advisories/BREW-biber-CVE-2026-7111.json | 92 +++++++ advisories/BREW-biber-CVE-2026-8594.json | 91 ++++++ .../BREW-bioperl-CPANSA-IPC-Run-2009-01.json | 65 +++++ advisories/BREW-bioperl-CVE-2016-9180.json | 78 ++++++ advisories/BREW-carton-CVE-2014-1875.json | 108 ++++++++ advisories/BREW-cloc-CVE-2011-4115.json | 69 +++++ advisories/BREW-cpm-CVE-2014-1875.json | 108 ++++++++ ...EW-exiftool-CPANSA-Mozilla-CA-2011-34.json | 69 +++++ advisories/BREW-exiftool-CVE-2014-1875.json | 108 ++++++++ advisories/BREW-exiftool-CVE-2020-36846.json | 156 +++++++++++ advisories/BREW-exiftool-CVE-2024-39689.json | 89 ++++++ ...extract_url-CPANSA-MIME-tools-1998-01.json | 61 ++++ .../BREW-extract_url-CVE-2009-3627.json | 92 +++++++ .../BREW-extract_url-CVE-2026-8829.json | 92 +++++++ advisories/BREW-fpdns-CVE-2007-3377.json | 180 ++++++++++++ advisories/BREW-fpdns-CVE-2007-3409.json | 178 ++++++++++++ advisories/BREW-fpdns-CVE-2007-6341.json | 104 +++++++ advisories/BREW-fpdns-CVE-2026-64193.json | 70 +++++ advisories/BREW-fpdns-CVE-2026-64194.json | 70 +++++ ...h-videos-CPANSA-WWW-Mechanize-2004-01.json | 61 ++++ ...ash-videos-CPANSA-libwww-perl-1995-01.json | 61 ++++ ...ash-videos-CPANSA-libwww-perl-2001-01.json | 55 ++++ ...ash-videos-CPANSA-libwww-perl-2017-01.json | 61 ++++ .../BREW-get-flash-videos-CVE-2010-2253.json | 96 +++++++ .../BREW-get-flash-videos-CVE-2011-0633.json | 68 +++++ .../BREW-get-flash-videos-CVE-2026-8368.json | 96 +++++++ ...et_iplayer-CPANSA-Mojolicious-2014-01.json | 61 ++++ ...et_iplayer-CPANSA-Mojolicious-2015-01.json | 65 +++++ ...et_iplayer-CPANSA-Mojolicious-2018-02.json | 65 +++++ ...et_iplayer-CPANSA-Mojolicious-2018-03.json | 65 +++++ ...et_iplayer-CPANSA-Mojolicious-2018-04.json | 61 ++++ ...et_iplayer-CPANSA-Mojolicious-2021-02.json | 58 ++++ ...et_iplayer-CPANSA-Mojolicious-2022-03.json | 66 +++++ ...get_iplayer-CPANSA-Mozilla-CA-2011-34.json | 69 +++++ .../BREW-get_iplayer-CVE-2009-3024.json | 88 ++++++ .../BREW-get_iplayer-CVE-2009-5074.json | 61 ++++ .../BREW-get_iplayer-CVE-2010-4334.json | 100 +++++++ .../BREW-get_iplayer-CVE-2010-4802.json | 76 +++++ .../BREW-get_iplayer-CVE-2010-4803.json | 68 +++++ .../BREW-get_iplayer-CVE-2011-1589.json | 148 ++++++++++ .../BREW-get_iplayer-CVE-2011-1841.json | 76 +++++ .../BREW-get_iplayer-CVE-2018-25100.json | 78 ++++++ .../BREW-get_iplayer-CVE-2020-36829.json | 71 +++++ .../BREW-get_iplayer-CVE-2021-47208.json | 67 +++++ .../BREW-get_iplayer-CVE-2024-39689.json | 86 ++++++ .../BREW-get_iplayer-CVE-2024-58134.json | 119 ++++++++ .../BREW-get_iplayer-CVE-2024-58135.json | 127 +++++++++ .../BREW-get_iplayer-CVE-2026-14803.json | 88 ++++++ .../BREW-get_iplayer-CVE-2026-15747.json | 88 ++++++ advisories/BREW-git-CVE-2025-40918.json | 103 +++++++ ...REW-kpcli-CPANSA-File-KeePass-2016-01.json | 57 ++++ advisories/BREW-kpcli-CVE-2014-1875.json | 108 ++++++++ advisories/BREW-kpcli-CVE-2014-2524.json | 93 +++++++ advisories/BREW-kpcli-CVE-2014-5509.json | 73 +++++ .../BREW-latexindent-CVE-2008-3502.json | 73 +++++ .../BREW-latexindent-CVE-2026-8594.json | 91 ++++++ .../BREW-libbi-CPANSA-File-Slurp-2013-01.json | 62 +++++ advisories/BREW-libbi-CVE-2026-5090.json | 88 ++++++ advisories/BREW-mhonarc-CVE-2010-1677.json | 101 +++++++ advisories/BREW-mhonarc-CVE-2010-4524.json | 137 +++++++++ .../BREW-monkeysphere-CVE-2024-2467.json | 75 +++++ ...BREW-moreutils-CPANSA-IPC-Run-2009-01.json | 65 +++++ .../BREW-notmuch-mutt-CVE-2014-2524.json | 93 +++++++ .../BREW-notmuch-mutt-CVE-2026-8594.json | 91 ++++++ ...W-perl-build-CPANSA-HTTP-Tiny-2013-01.json | 61 ++++ advisories/BREW-perl-build-CVE-2016-1238.json | 122 ++++++++ .../BREW-perl-build-CVE-2023-31486.json | 111 ++++++++ advisories/BREW-perl-build-CVE-2026-7010.json | 88 ++++++ advisories/BREW-perl-build-CVE-2026-7017.json | 100 +++++++ .../BREW-perl-dbd-mysql-CVE-2014-9906.json | 99 +++++++ .../BREW-perl-dbd-mysql-CVE-2015-8949.json | 111 ++++++++ .../BREW-perl-xml-parser-CVE-2006-10002.json | 78 ++++++ .../BREW-perl-xml-parser-CVE-2006-10003.json | 70 +++++ advisories/BREW-po4a-CVE-2026-8594.json | 91 ++++++ advisories/BREW-rex-CVE-2021-29662.json | 86 ++++++ .../BREW-texlive-CPANSA-CGI-2010-01.json | 55 ++++ .../BREW-texlive-CPANSA-CGI-2010-02.json | 55 ++++ ...REW-texlive-CPANSA-Mozilla-CA-2011-34.json | 69 +++++ ...-texlive-CPANSA-WWW-Mechanize-2004-01.json | 61 ++++ ...EW-texlive-CPANSA-libwww-perl-1995-01.json | 61 ++++ ...EW-texlive-CPANSA-libwww-perl-2001-01.json | 55 ++++ ...EW-texlive-CPANSA-libwww-perl-2017-01.json | 61 ++++ advisories/BREW-texlive-CVE-2005-0106.json | 72 +++++ advisories/BREW-texlive-CVE-2006-4484.json | 260 ++++++++++++++++++ advisories/BREW-texlive-CVE-2007-4769.json | 205 ++++++++++++++ advisories/BREW-texlive-CVE-2009-3024.json | 88 ++++++ advisories/BREW-texlive-CVE-2009-3627.json | 92 +++++++ advisories/BREW-texlive-CVE-2010-2253.json | 96 +++++++ advisories/BREW-texlive-CVE-2010-2761.json | 196 +++++++++++++ advisories/BREW-texlive-CVE-2010-4334.json | 100 +++++++ advisories/BREW-texlive-CVE-2010-4411.json | 116 ++++++++ advisories/BREW-texlive-CVE-2011-0633.json | 68 +++++ advisories/BREW-texlive-CVE-2011-2766.json | 136 +++++++++ advisories/BREW-texlive-CVE-2012-5526.json | 112 ++++++++ advisories/BREW-texlive-CVE-2014-3230.json | 110 ++++++++ advisories/BREW-texlive-CVE-2016-10087.json | 98 +++++++ advisories/BREW-texlive-CVE-2022-31081.json | 116 ++++++++ advisories/BREW-texlive-CVE-2023-7101.json | 110 ++++++++ advisories/BREW-texlive-CVE-2024-39689.json | 89 ++++++ advisories/BREW-texlive-CVE-2026-14741.json | 92 +++++++ advisories/BREW-texlive-CVE-2026-8368.json | 96 +++++++ advisories/BREW-texlive-CVE-2026-8450.json | 120 ++++++++ advisories/BREW-texlive-CVE-2026-8829.json | 92 +++++++ data/rejected-candidates.txt | 133 --------- 129 files changed, 11383 insertions(+), 133 deletions(-) create mode 100644 advisories/BREW-abcde-CPANSA-Mojolicious-2014-01.json create mode 100644 advisories/BREW-abcde-CPANSA-Mojolicious-2015-01.json create mode 100644 advisories/BREW-abcde-CPANSA-Mojolicious-2018-02.json create mode 100644 advisories/BREW-abcde-CPANSA-Mojolicious-2018-03.json create mode 100644 advisories/BREW-abcde-CPANSA-Mojolicious-2018-04.json create mode 100644 advisories/BREW-abcde-CPANSA-Mojolicious-2021-02.json create mode 100644 advisories/BREW-abcde-CPANSA-Mojolicious-2022-03.json create mode 100644 advisories/BREW-abcde-CVE-2009-5074.json create mode 100644 advisories/BREW-abcde-CVE-2010-4802.json create mode 100644 advisories/BREW-abcde-CVE-2010-4803.json create mode 100644 advisories/BREW-abcde-CVE-2011-1589.json create mode 100644 advisories/BREW-abcde-CVE-2011-1841.json create mode 100644 advisories/BREW-abcde-CVE-2018-25100.json create mode 100644 advisories/BREW-abcde-CVE-2020-36829.json create mode 100644 advisories/BREW-abcde-CVE-2021-47208.json create mode 100644 advisories/BREW-abcde-CVE-2024-58134.json create mode 100644 advisories/BREW-abcde-CVE-2024-58135.json create mode 100644 advisories/BREW-abcde-CVE-2026-14803.json create mode 100644 advisories/BREW-abcde-CVE-2026-15747.json create mode 100644 advisories/BREW-amtterm-CPANSA-SOAP-Lite-2000-01.json create mode 100644 advisories/BREW-amtterm-CVE-2002-1742.json create mode 100644 advisories/BREW-amtterm-CVE-2015-8978.json create mode 100644 advisories/BREW-biber-CPANSA-Mozilla-CA-2011-34.json create mode 100644 advisories/BREW-biber-CVE-2024-39689.json create mode 100644 advisories/BREW-biber-CVE-2026-12844.json create mode 100644 advisories/BREW-biber-CVE-2026-7111.json create mode 100644 advisories/BREW-biber-CVE-2026-8594.json create mode 100644 advisories/BREW-bioperl-CPANSA-IPC-Run-2009-01.json create mode 100644 advisories/BREW-bioperl-CVE-2016-9180.json create mode 100644 advisories/BREW-carton-CVE-2014-1875.json create mode 100644 advisories/BREW-cloc-CVE-2011-4115.json create mode 100644 advisories/BREW-cpm-CVE-2014-1875.json create mode 100644 advisories/BREW-exiftool-CPANSA-Mozilla-CA-2011-34.json create mode 100644 advisories/BREW-exiftool-CVE-2014-1875.json create mode 100644 advisories/BREW-exiftool-CVE-2020-36846.json create mode 100644 advisories/BREW-exiftool-CVE-2024-39689.json create mode 100644 advisories/BREW-extract_url-CPANSA-MIME-tools-1998-01.json create mode 100644 advisories/BREW-extract_url-CVE-2009-3627.json create mode 100644 advisories/BREW-extract_url-CVE-2026-8829.json create mode 100644 advisories/BREW-fpdns-CVE-2007-3377.json create mode 100644 advisories/BREW-fpdns-CVE-2007-3409.json create mode 100644 advisories/BREW-fpdns-CVE-2007-6341.json create mode 100644 advisories/BREW-fpdns-CVE-2026-64193.json create mode 100644 advisories/BREW-fpdns-CVE-2026-64194.json create mode 100644 advisories/BREW-get-flash-videos-CPANSA-WWW-Mechanize-2004-01.json create mode 100644 advisories/BREW-get-flash-videos-CPANSA-libwww-perl-1995-01.json create mode 100644 advisories/BREW-get-flash-videos-CPANSA-libwww-perl-2001-01.json create mode 100644 advisories/BREW-get-flash-videos-CPANSA-libwww-perl-2017-01.json create mode 100644 advisories/BREW-get-flash-videos-CVE-2010-2253.json create mode 100644 advisories/BREW-get-flash-videos-CVE-2011-0633.json create mode 100644 advisories/BREW-get-flash-videos-CVE-2026-8368.json create mode 100644 advisories/BREW-get_iplayer-CPANSA-Mojolicious-2014-01.json create mode 100644 advisories/BREW-get_iplayer-CPANSA-Mojolicious-2015-01.json create mode 100644 advisories/BREW-get_iplayer-CPANSA-Mojolicious-2018-02.json create mode 100644 advisories/BREW-get_iplayer-CPANSA-Mojolicious-2018-03.json create mode 100644 advisories/BREW-get_iplayer-CPANSA-Mojolicious-2018-04.json create mode 100644 advisories/BREW-get_iplayer-CPANSA-Mojolicious-2021-02.json create mode 100644 advisories/BREW-get_iplayer-CPANSA-Mojolicious-2022-03.json create mode 100644 advisories/BREW-get_iplayer-CPANSA-Mozilla-CA-2011-34.json create mode 100644 advisories/BREW-get_iplayer-CVE-2009-3024.json create mode 100644 advisories/BREW-get_iplayer-CVE-2009-5074.json create mode 100644 advisories/BREW-get_iplayer-CVE-2010-4334.json create mode 100644 advisories/BREW-get_iplayer-CVE-2010-4802.json create mode 100644 advisories/BREW-get_iplayer-CVE-2010-4803.json create mode 100644 advisories/BREW-get_iplayer-CVE-2011-1589.json create mode 100644 advisories/BREW-get_iplayer-CVE-2011-1841.json create mode 100644 advisories/BREW-get_iplayer-CVE-2018-25100.json create mode 100644 advisories/BREW-get_iplayer-CVE-2020-36829.json create mode 100644 advisories/BREW-get_iplayer-CVE-2021-47208.json create mode 100644 advisories/BREW-get_iplayer-CVE-2024-39689.json create mode 100644 advisories/BREW-get_iplayer-CVE-2024-58134.json create mode 100644 advisories/BREW-get_iplayer-CVE-2024-58135.json create mode 100644 advisories/BREW-get_iplayer-CVE-2026-14803.json create mode 100644 advisories/BREW-get_iplayer-CVE-2026-15747.json create mode 100644 advisories/BREW-git-CVE-2025-40918.json create mode 100644 advisories/BREW-kpcli-CPANSA-File-KeePass-2016-01.json create mode 100644 advisories/BREW-kpcli-CVE-2014-1875.json create mode 100644 advisories/BREW-kpcli-CVE-2014-2524.json create mode 100644 advisories/BREW-kpcli-CVE-2014-5509.json create mode 100644 advisories/BREW-latexindent-CVE-2008-3502.json create mode 100644 advisories/BREW-latexindent-CVE-2026-8594.json create mode 100644 advisories/BREW-libbi-CPANSA-File-Slurp-2013-01.json create mode 100644 advisories/BREW-libbi-CVE-2026-5090.json create mode 100644 advisories/BREW-mhonarc-CVE-2010-1677.json create mode 100644 advisories/BREW-mhonarc-CVE-2010-4524.json create mode 100644 advisories/BREW-monkeysphere-CVE-2024-2467.json create mode 100644 advisories/BREW-moreutils-CPANSA-IPC-Run-2009-01.json create mode 100644 advisories/BREW-notmuch-mutt-CVE-2014-2524.json create mode 100644 advisories/BREW-notmuch-mutt-CVE-2026-8594.json create mode 100644 advisories/BREW-perl-build-CPANSA-HTTP-Tiny-2013-01.json create mode 100644 advisories/BREW-perl-build-CVE-2016-1238.json create mode 100644 advisories/BREW-perl-build-CVE-2023-31486.json create mode 100644 advisories/BREW-perl-build-CVE-2026-7010.json create mode 100644 advisories/BREW-perl-build-CVE-2026-7017.json create mode 100644 advisories/BREW-perl-dbd-mysql-CVE-2014-9906.json create mode 100644 advisories/BREW-perl-dbd-mysql-CVE-2015-8949.json create mode 100644 advisories/BREW-perl-xml-parser-CVE-2006-10002.json create mode 100644 advisories/BREW-perl-xml-parser-CVE-2006-10003.json create mode 100644 advisories/BREW-po4a-CVE-2026-8594.json create mode 100644 advisories/BREW-rex-CVE-2021-29662.json create mode 100644 advisories/BREW-texlive-CPANSA-CGI-2010-01.json create mode 100644 advisories/BREW-texlive-CPANSA-CGI-2010-02.json create mode 100644 advisories/BREW-texlive-CPANSA-Mozilla-CA-2011-34.json create mode 100644 advisories/BREW-texlive-CPANSA-WWW-Mechanize-2004-01.json create mode 100644 advisories/BREW-texlive-CPANSA-libwww-perl-1995-01.json create mode 100644 advisories/BREW-texlive-CPANSA-libwww-perl-2001-01.json create mode 100644 advisories/BREW-texlive-CPANSA-libwww-perl-2017-01.json create mode 100644 advisories/BREW-texlive-CVE-2005-0106.json create mode 100644 advisories/BREW-texlive-CVE-2006-4484.json create mode 100644 advisories/BREW-texlive-CVE-2007-4769.json create mode 100644 advisories/BREW-texlive-CVE-2009-3024.json create mode 100644 advisories/BREW-texlive-CVE-2009-3627.json create mode 100644 advisories/BREW-texlive-CVE-2010-2253.json create mode 100644 advisories/BREW-texlive-CVE-2010-2761.json create mode 100644 advisories/BREW-texlive-CVE-2010-4334.json create mode 100644 advisories/BREW-texlive-CVE-2010-4411.json create mode 100644 advisories/BREW-texlive-CVE-2011-0633.json create mode 100644 advisories/BREW-texlive-CVE-2011-2766.json create mode 100644 advisories/BREW-texlive-CVE-2012-5526.json create mode 100644 advisories/BREW-texlive-CVE-2014-3230.json create mode 100644 advisories/BREW-texlive-CVE-2016-10087.json create mode 100644 advisories/BREW-texlive-CVE-2022-31081.json create mode 100644 advisories/BREW-texlive-CVE-2023-7101.json create mode 100644 advisories/BREW-texlive-CVE-2024-39689.json create mode 100644 advisories/BREW-texlive-CVE-2026-14741.json create mode 100644 advisories/BREW-texlive-CVE-2026-8368.json create mode 100644 advisories/BREW-texlive-CVE-2026-8450.json create mode 100644 advisories/BREW-texlive-CVE-2026-8829.json diff --git a/advisories/BREW-abcde-CPANSA-Mojolicious-2014-01.json b/advisories/BREW-abcde-CPANSA-Mojolicious-2014-01.json new file mode 100644 index 0000000000..f0d39fbe08 --- /dev/null +++ b/advisories/BREW-abcde-CPANSA-Mojolicious-2014-01.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-abcde-CPANSA-Mojolicious-2014-01", + "published": "2026-08-13T09:10:09Z", + "modified": "2026-08-13T09:10:09Z", + "upstream": [ + "CPANSA-Mojolicious-2014-01" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "abcde", + "purl": "pkg:brew/abcde" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.9.3_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "5.48", + "resource": "Mojo::Base", + "resource_purl": "pkg:cpan/SRI/Mojolicious@8.64" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "cpansa", + "confidence": "medium", + "upstream_evidence": [ + { + "strategy": "cpansa", + "ecosystem": "CPAN", + "name": "Mojolicious", + "subject_version": "8.64", + "key": "pkg:cpan/SRI/Mojolicious@8.64", + "resource": "Mojo::Base" + } + ] + }, + "summary": "Context sensitivity of method param could lead to parameter injection attacks.", + "details": "Context sensitivity of method param could lead to parameter injection attacks.\n", + "references": [ + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/commit/a815d4797145f872ef6e9f1270841eda1d410afb" + } + ] +} diff --git a/advisories/BREW-abcde-CPANSA-Mojolicious-2015-01.json b/advisories/BREW-abcde-CPANSA-Mojolicious-2015-01.json new file mode 100644 index 0000000000..856a335a38 --- /dev/null +++ b/advisories/BREW-abcde-CPANSA-Mojolicious-2015-01.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-abcde-CPANSA-Mojolicious-2015-01", + "published": "2026-08-13T09:10:09Z", + "modified": "2026-08-13T09:10:09Z", + "upstream": [ + "CPANSA-Mojolicious-2015-01" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "abcde", + "purl": "pkg:brew/abcde" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.9.3_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "5.76", + "resource": "Mojo::Base", + "resource_purl": "pkg:cpan/SRI/Mojolicious@8.64" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "cpansa", + "confidence": "medium", + "upstream_evidence": [ + { + "strategy": "cpansa", + "ecosystem": "CPAN", + "name": "Mojolicious", + "subject_version": "8.64", + "key": "pkg:cpan/SRI/Mojolicious@8.64", + "resource": "Mojo::Base" + } + ] + }, + "summary": "Directory traversal on Windows", + "details": "Directory traversal on Windows\n", + "references": [ + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/issues/738" + }, + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/commit/9ffa38fca73a9ddee91cbc70e0696268d500edde" + } + ] +} diff --git a/advisories/BREW-abcde-CPANSA-Mojolicious-2018-02.json b/advisories/BREW-abcde-CPANSA-Mojolicious-2018-02.json new file mode 100644 index 0000000000..9c160b444a --- /dev/null +++ b/advisories/BREW-abcde-CPANSA-Mojolicious-2018-02.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-abcde-CPANSA-Mojolicious-2018-02", + "published": "2026-08-13T09:10:09Z", + "modified": "2026-08-13T09:10:09Z", + "upstream": [ + "CPANSA-Mojolicious-2018-02" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "abcde", + "purl": "pkg:brew/abcde" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.9.3_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "7.78", + "resource": "Mojo::Base", + "resource_purl": "pkg:cpan/SRI/Mojolicious@8.64" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "cpansa", + "confidence": "medium", + "upstream_evidence": [ + { + "strategy": "cpansa", + "ecosystem": "CPAN", + "name": "Mojolicious", + "subject_version": "8.64", + "key": "pkg:cpan/SRI/Mojolicious@8.64", + "resource": "Mojo::Base" + } + ] + }, + "summary": "GET requests with embedded backslashes can be used to access local files on Windows hosts", + "details": "GET requests with embedded backslashes can be used to access local files on Windows hosts\n", + "references": [ + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/pull/1217" + }, + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/commit/23ebe051d9378f0f122e3c908845fc0c2cae0106" + } + ] +} diff --git a/advisories/BREW-abcde-CPANSA-Mojolicious-2018-03.json b/advisories/BREW-abcde-CPANSA-Mojolicious-2018-03.json new file mode 100644 index 0000000000..412dd8a2b1 --- /dev/null +++ b/advisories/BREW-abcde-CPANSA-Mojolicious-2018-03.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-abcde-CPANSA-Mojolicious-2018-03", + "published": "2026-08-13T09:10:09Z", + "modified": "2026-08-13T09:10:09Z", + "upstream": [ + "CPANSA-Mojolicious-2018-03" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "abcde", + "purl": "pkg:brew/abcde" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.9.3_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "7.80", + "resource": "Mojo::Base", + "resource_purl": "pkg:cpan/SRI/Mojolicious@8.64" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "cpansa", + "confidence": "medium", + "upstream_evidence": [ + { + "strategy": "cpansa", + "ecosystem": "CPAN", + "name": "Mojolicious", + "subject_version": "8.64", + "key": "pkg:cpan/SRI/Mojolicious@8.64", + "resource": "Mojo::Base" + } + ] + }, + "summary": "Mojo::UserAgent was not checking peer SSL certificates by default.", + "details": "Mojo::UserAgent was not checking peer SSL certificates by default.\n", + "references": [ + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/pull/1226" + }, + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/commit/d3cbbad890673612fdbdea63fdd522b516f6104c" + } + ] +} diff --git a/advisories/BREW-abcde-CPANSA-Mojolicious-2018-04.json b/advisories/BREW-abcde-CPANSA-Mojolicious-2018-04.json new file mode 100644 index 0000000000..490be064ce --- /dev/null +++ b/advisories/BREW-abcde-CPANSA-Mojolicious-2018-04.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-abcde-CPANSA-Mojolicious-2018-04", + "published": "2026-08-13T09:10:09Z", + "modified": "2026-08-13T09:10:09Z", + "upstream": [ + "CPANSA-Mojolicious-2018-04" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "abcde", + "purl": "pkg:brew/abcde" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.9.3_1" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "7.92", + "resource": "Mojo::Base", + "resource_purl": "pkg:cpan/SRI/Mojolicious@8.64" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "cpansa", + "confidence": "medium", + "upstream_evidence": [ + { + "strategy": "cpansa", + "ecosystem": "CPAN", + "name": "Mojolicious", + "subject_version": "8.64", + "key": "pkg:cpan/SRI/Mojolicious@8.64", + "resource": "Mojo::Base" + } + ] + }, + "summary": "This release reverts the addition of stream classes (added in 7.83), which have unfortunately resulted in many Mojolicious applications becoming unstable. While there are no known exploits yet, we've chosen to err on the side of cautiousness and will classify this as a security issue.", + "details": "This release reverts the addition of stream classes (added in 7.83), which have unfortunately resulted in many Mojolicious applications becoming unstable. While there are no known exploits yet, we've chosen to err on the side of cautiousness and will classify this as a security issue.\n", + "references": [ + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/commit/61f6cbf22c7bf8eb4787bd1014d91ee2416c73e7" + } + ] +} diff --git a/advisories/BREW-abcde-CPANSA-Mojolicious-2021-02.json b/advisories/BREW-abcde-CPANSA-Mojolicious-2021-02.json new file mode 100644 index 0000000000..6f564fc741 --- /dev/null +++ b/advisories/BREW-abcde-CPANSA-Mojolicious-2021-02.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-abcde-CPANSA-Mojolicious-2021-02", + "published": "2026-08-13T09:10:09Z", + "modified": "2026-08-13T09:10:09Z", + "upstream": [ + "CPANSA-Mojolicious-2021-02" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "abcde", + "purl": "pkg:brew/abcde" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "9.91", + "resource": "Mojo::Base", + "resource_purl": "pkg:cpan/SRI/Mojolicious@8.64" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "cpansa", + "confidence": "medium", + "upstream_evidence": [ + { + "strategy": "cpansa", + "ecosystem": "CPAN", + "name": "Mojolicious", + "subject_version": "8.64", + "key": "pkg:cpan/SRI/Mojolicious@8.64", + "resource": "Mojo::Base" + } + ] + }, + "summary": "Small sessions could be used as part of a brute-force attack to decode the session secret.", + "details": "Small sessions could be used as part of a brute-force attack to decode the session secret.\n", + "references": [ + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/pull/1791" + } + ] +} diff --git a/advisories/BREW-abcde-CPANSA-Mojolicious-2022-03.json b/advisories/BREW-abcde-CPANSA-Mojolicious-2022-03.json new file mode 100644 index 0000000000..a23c0bb736 --- /dev/null +++ b/advisories/BREW-abcde-CPANSA-Mojolicious-2022-03.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-abcde-CPANSA-Mojolicious-2022-03", + "published": "2026-08-13T09:10:09Z", + "modified": "2026-08-13T09:10:09Z", + "upstream": [ + "CPANSA-Mojolicious-2022-03" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "abcde", + "purl": "pkg:brew/abcde" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "9.31", + "resource": "Mojo::Base", + "resource_purl": "pkg:cpan/SRI/Mojolicious@8.64" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "cpansa", + "confidence": "medium", + "upstream_evidence": [ + { + "strategy": "cpansa", + "ecosystem": "CPAN", + "name": "Mojolicious", + "subject_version": "8.64", + "key": "pkg:cpan/SRI/Mojolicious@8.64", + "resource": "Mojo::Base" + } + ] + }, + "summary": "Mojo::DOM did not correctly parse