Skip to content

Commit 8ca142d

Browse files
Advisory Database Sync
1 parent d82cdb6 commit 8ca142d

37 files changed

Lines changed: 722 additions & 53 deletions

File tree

advisories/unreviewed/2022/05/GHSA-fw8c-q6fq-37rg/GHSA-fw8c-q6fq-37rg.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-fw8c-q6fq-37rg",
4-
"modified": "2022-05-13T01:34:54Z",
4+
"modified": "2026-07-07T15:32:47Z",
55
"published": "2022-05-13T01:34:54Z",
66
"aliases": [
77
"CVE-2018-10902"

advisories/unreviewed/2026/03/GHSA-hq85-3f6c-jx84/GHSA-hq85-3f6c-jx84.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-hq85-3f6c-jx84",
4-
"modified": "2026-06-22T21:30:45Z",
4+
"modified": "2026-07-07T15:32:50Z",
55
"published": "2026-03-26T21:31:27Z",
66
"aliases": [
77
"CVE-2026-2100"
@@ -54,6 +54,10 @@
5454
{
5555
"type": "WEB",
5656
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2437308"
57+
},
58+
{
59+
"type": "WEB",
60+
"url": "https://github.com/p11-glue/p11-kit/releases/tag/0.26.2"
5761
}
5862
],
5963
"database_specific": {

advisories/unreviewed/2026/05/GHSA-9gx7-g5hv-xjjj/GHSA-9gx7-g5hv-xjjj.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-9gx7-g5hv-xjjj",
4-
"modified": "2026-07-06T21:30:25Z",
4+
"modified": "2026-07-07T15:32:51Z",
55
"published": "2026-05-18T15:30:37Z",
66
"aliases": [
77
"CVE-2026-42009"
@@ -47,6 +47,10 @@
4747
"type": "WEB",
4848
"url": "https://access.redhat.com/errata/RHSA-2026:36004"
4949
},
50+
{
51+
"type": "WEB",
52+
"url": "https://access.redhat.com/errata/RHSA-2026:34764"
53+
},
5054
{
5155
"type": "WEB",
5256
"url": "https://access.redhat.com/errata/RHSA-2026:34372"

advisories/unreviewed/2026/05/GHSA-m3r7-xjq8-gc4r/GHSA-m3r7-xjq8-gc4r.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-m3r7-xjq8-gc4r",
4-
"modified": "2026-07-07T12:31:29Z",
4+
"modified": "2026-07-07T15:32:51Z",
55
"published": "2026-05-07T12:31:23Z",
66
"aliases": [
77
"CVE-2026-42010"
@@ -51,6 +51,10 @@
5151
"type": "WEB",
5252
"url": "https://access.redhat.com/errata/RHSA-2026:34790"
5353
},
54+
{
55+
"type": "WEB",
56+
"url": "https://access.redhat.com/errata/RHSA-2026:34764"
57+
},
5458
{
5559
"type": "WEB",
5660
"url": "https://access.redhat.com/errata/RHSA-2026:33125"

advisories/unreviewed/2026/06/GHSA-3xcp-963x-rf7x/GHSA-3xcp-963x-rf7x.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,17 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-3xcp-963x-rf7x",
4-
"modified": "2026-06-12T06:33:21Z",
4+
"modified": "2026-07-07T15:32:50Z",
55
"published": "2026-06-12T06:33:20Z",
66
"aliases": [
77
"CVE-2026-45169"
88
],
99
"details": "Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17",
1010
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
14+
},
1115
{
1216
"type": "CVSS_V4",
1317
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber"

advisories/unreviewed/2026/06/GHSA-6mrg-rm5v-2c3q/GHSA-6mrg-rm5v-2c3q.json

Lines changed: 33 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-6mrg-rm5v-2c3q",
4-
"modified": "2026-06-30T03:37:01Z",
4+
"modified": "2026-07-07T15:32:50Z",
55
"published": "2026-06-11T21:31:56Z",
66
"aliases": [
77
"CVE-2026-11774"
@@ -19,6 +19,38 @@
1919
"type": "ADVISORY",
2020
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11774"
2121
},
22+
{
23+
"type": "WEB",
24+
"url": "https://access.redhat.com/errata/RHSA-2026:36197"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://access.redhat.com/errata/RHSA-2026:36198"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://access.redhat.com/errata/RHSA-2026:36201"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://access.redhat.com/errata/RHSA-2026:36202"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://access.redhat.com/errata/RHSA-2026:36204"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://access.redhat.com/errata/RHSA-2026:36205"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://access.redhat.com/errata/RHSA-2026:36206"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://access.redhat.com/errata/RHSA-2026:36208"
53+
},
2254
{
2355
"type": "WEB",
2456
"url": "https://access.redhat.com/security/cve/CVE-2026-11774"

advisories/unreviewed/2026/06/GHSA-vx9j-g89f-rrvx/GHSA-vx9j-g89f-rrvx.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,17 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-vx9j-g89f-rrvx",
4-
"modified": "2026-06-11T00:32:04Z",
4+
"modified": "2026-07-07T15:32:50Z",
55
"published": "2026-06-11T00:32:04Z",
66
"aliases": [
77
"CVE-2026-0267"
88
],
99
"details": "An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.",
1010
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
14+
},
1115
{
1216
"type": "CVSS_V4",
1317
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber"

advisories/unreviewed/2026/07/GHSA-22hf-vx2v-gjff/GHSA-22hf-vx2v-gjff.json

Lines changed: 12 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-22hf-vx2v-gjff",
4-
"modified": "2026-07-07T12:31:36Z",
4+
"modified": "2026-07-07T15:32:56Z",
55
"published": "2026-07-07T12:31:36Z",
66
"aliases": [
77
"CVE-2026-49487"
88
],
99
"details": "In Apache Airflow before 3.3.0, the REST API task-instance detail and list\nendpoints returned a deferred task's trigger kwargs without masking. When a\ndeferred operator passed a secret (for example a provider API key) into its\ntrigger, any authenticated user with DAG-scoped task-instance read access for\nthat DAG could read that secret in clear text while the task was deferred.\nUsers should upgrade to apache-airflow 3.3.0 or later, which masks sensitive\nvalues in trigger kwargs returned by the API.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -21,13 +26,17 @@
2126
{
2227
"type": "WEB",
2328
"url": "https://lists.apache.org/thread/qlw6pozlzlfhkvmbgqsbjlq6vj4v0pc4"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "http://www.openwall.com/lists/oss-security/2026/07/07/6"
2433
}
2534
],
2635
"database_specific": {
2736
"cwe_ids": [
2837
"CWE-200"
2938
],
30-
"severity": null,
39+
"severity": "MODERATE",
3140
"github_reviewed": false,
3241
"github_reviewed_at": null,
3342
"nvd_published_at": "2026-07-07T10:16:41Z"

advisories/unreviewed/2026/07/GHSA-2943-9672-r45w/GHSA-2943-9672-r45w.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-2943-9672-r45w",
4-
"modified": "2026-07-07T12:31:35Z",
4+
"modified": "2026-07-07T15:32:56Z",
55
"published": "2026-07-07T12:31:35Z",
66
"aliases": [
77
"CVE-2026-33264"
@@ -25,6 +25,10 @@
2525
{
2626
"type": "WEB",
2727
"url": "https://lists.apache.org/thread/otvdw8qt2y7xy2n5nq9xby9ky4rf5ltj"
28+
},
29+
{
30+
"type": "WEB",
31+
"url": "http://www.openwall.com/lists/oss-security/2026/07/07/1"
2832
}
2933
],
3034
"database_specific": {

advisories/unreviewed/2026/07/GHSA-2g8g-f92j-g4gq/GHSA-2g8g-f92j-g4gq.json

Lines changed: 33 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-2g8g-f92j-g4gq",
4-
"modified": "2026-07-07T12:31:35Z",
4+
"modified": "2026-07-07T15:32:57Z",
55
"published": "2026-07-07T12:31:35Z",
66
"aliases": [
77
"CVE-2026-11610"
@@ -19,6 +19,38 @@
1919
"type": "ADVISORY",
2020
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11610"
2121
},
22+
{
23+
"type": "WEB",
24+
"url": "https://access.redhat.com/errata/RHSA-2026:36197"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://access.redhat.com/errata/RHSA-2026:36198"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://access.redhat.com/errata/RHSA-2026:36201"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://access.redhat.com/errata/RHSA-2026:36202"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://access.redhat.com/errata/RHSA-2026:36204"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://access.redhat.com/errata/RHSA-2026:36205"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://access.redhat.com/errata/RHSA-2026:36206"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://access.redhat.com/errata/RHSA-2026:36208"
53+
},
2254
{
2355
"type": "WEB",
2456
"url": "https://access.redhat.com/security/cve/CVE-2026-11610"

0 commit comments

Comments
 (0)